June 2015

SLES 12 โ€” gv โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on SLES 12

SLES 12 โ€” gv โ€” vulnerability โ€” patch and remediation guide

๐ŸŸก Medium   โฑ 10โ€“30 min  Last verified: 25 May 2026 Affected versions: SLES 12 ๐Ÿ“– ~4 min read  โ€ข  Source: SUSE advisory SUSE-SU-2013:1329-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-3386 Upstream summary: The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces […]

Read more
Ubuntu 14.04 โ€” network-manager-applet โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 โ€” network-manager-applet โ€” vulnerability โ€” patch and remediation guide

๐ŸŸข Low   โฑ 5โ€“15 min  Last verified: 25 May 2026 Affected versions: Ubuntu 14.04 (trusty) ๐Ÿ“– ~4 min read  โ€ข  Source: Ubuntu Security Notice USN-3217-1 Related CVEs: https://launchpad.net/bugs/1668321 Upstream summary: Frederic Bardy and Quentin Biguenet discovered that network-manager-applet incorrectly checked permissions when connecting to certain wireless networks. A local attacker could use this issue […]

Read more
SLES 12 โ€” python-imaging โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on SLES 12

SLES 12 โ€” python-imaging โ€” vulnerability โ€” patch and remediation guide

๐ŸŸก Medium   โฑ 10โ€“30 min  Last verified: 25 May 2026 Affected versions: SLES 12 ๐Ÿ“– ~4 min read  โ€ข  Source: SUSE advisory SUSE-SU-2014:0705-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-1932 Upstream summary: The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py […]

Read more
Ubuntu 14.04 โ€” nvidia-graphics-drivers-340-updates โ€” multiple vulnerabilities (2 CVEs) โ€” patch and remediation guide โ€” diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 โ€” nvidia-graphics-drivers-340-updates โ€” multiple vulnerabilities (2 CVEs) โ€” patch and remediation guide

๐ŸŸข Low   โฑ 5โ€“15 min  Last verified: 25 May 2026 Affected versions: Ubuntu 14.04 (trusty) ๐Ÿ“– ~4 min read  โ€ข  Source: Ubuntu Security Notice USN-2814-1 Related CVEs: CVE-2015-7869 CVE-2015-5950 Upstream summary: It was discovered that the NVIDIA graphics drivers incorrectly sanitized user mode inputs. A local attacker could use this issue to possibly gain […]

Read more
Ubuntu 14.04 โ€” unity-settings-daemon โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 โ€” unity-settings-daemon โ€” vulnerability โ€” patch and remediation guide

๐ŸŸข Low   โฑ 5โ€“15 min  Last verified: 25 May 2026 Affected versions: Ubuntu 14.04 (trusty) ๐Ÿ“– ~4 min read  โ€ข  Source: Ubuntu Security Notice USN-2741-1 Related CVEs: CVE-2015-1319 Upstream summary: It was discovered that the Unity Settings Daemon incorrectly allowed removable media to be mounted when the screen is locked. If a vulnerability were […]

Read more
SLES 12 โ€” libmusicbrainz4 โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on SLES 12

SLES 12 โ€” libmusicbrainz4 โ€” vulnerability โ€” patch and remediation guide

๐ŸŸก Medium   โฑ 10โ€“30 min  Last verified: 25 May 2026 Affected versions: SLES 12 ๐Ÿ“– ~4 min read  โ€ข  Source: SUSE advisory SUSE-SR:2006:025 (see also SUSE bugzilla) Related CVEs: CVE-2006-4197 Upstream summary: Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers […]

Read more
SLES 12 โ€” systemtap โ€” multiple vulnerabilities (4 CVEs) โ€” patch and remediation guide โ€” diagnosis and fix on SLES 12

SLES 12 โ€” systemtap โ€” multiple vulnerabilities (4 CVEs) โ€” patch and remediation guide

๐ŸŸ  High   โฑ 15โ€“60 min  Last verified: 25 May 2026 Affected versions: SLES 12 ๐Ÿ“– ~4 min read  โ€ข  Source: SUSE advisory SUSE-SR:2010:010 (see also SUSE bugzilla) Related CVEs: CVE-2009-4273 CVE-2010-0412 CVE-2009-2911 CVE-2010-0411 Upstream summary: stap-server in SystemTap before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in stap command-line arguments […]

Read more
Ubuntu 14.04 โ€” heat โ€” vulnerability โ€” patch and remediation guide โ€” diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 โ€” heat โ€” vulnerability โ€” patch and remediation guide

๐ŸŸข Low   โฑ 5โ€“15 min  Last verified: 25 May 2026 Affected versions: Ubuntu 14.04 (trusty) ๐Ÿ“– ~4 min read  โ€ข  Source: Ubuntu Security Notice USN-2249-1 Related CVEs: CVE-2014-3801 Upstream summary: Jason Dunsmore discovered that OpenStack heat did not properly restrict access to template information. A remote authenticated attacker could exploit this to see URL […]

Read more
Ubuntu 14.04 โ€” simplestreams โ€” multiple vulnerabilities (2 CVEs) โ€” patch and remediation guide โ€” diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 โ€” simplestreams โ€” multiple vulnerabilities (2 CVEs) โ€” patch and remediation guide

๐ŸŸข Low   โฑ 5โ€“15 min  Last verified: 25 May 2026 Affected versions: Ubuntu 14.04 (trusty) ๐Ÿ“– ~4 min read  โ€ข  Source: Ubuntu Security Notice USN-2746-2 Related CVEs: https://launchpad.net/bugs/1499749 CVE-2015-1337 Upstream summary: USN-2746-1 fixed a vulnerability in Simple Streams. The update caused a regression preventing MAAS from downloading PXE images. This update fixes the problem. […]

Read more
CHAT