chris

Ubuntu 14.04 — memcached — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — memcached — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 January 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3601-1 Related CVEs: CVE-2018-1000127 CVE-2017-9951 CVE-2018-1000115 CVE-2016-8704 CVE-2016-8705 CVE-2016-8706 Upstream summary: It was discovered that Memcached incorrectly handled reusing certain items. A remote attacker could possibly use this issue to […]

Read more
FreeBSD 12 — libofx — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libofx — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libofx — exploitable buffer overflow Related CVEs: CVE-2017-2816 Upstream summary: Talos developers report: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted […]

Read more
FreeBSD 12 — gnu-finger — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gnu-finger — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GNU finger vulnerability Related CVEs: CVE-1999-1165 Upstream summary: GNU security announcement: GNU Finger unfortunately has not been updated in many years, and has known security vulnerabilities. Please do not use […]

Read more
Ubuntu 18.04 — prosody — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — prosody — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4834-1 Related CVEs: CVE-2018-10847 Upstream summary: It was discovered that Prosody incorrectly validated the virtual host associated with a user session across stream restarts. A remote attacker could use this […]

Read more
SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:005 (see also SUSE bugzilla) Related CVEs: CVE-2011-0541 CVE-2015-3202 CVE-2018-10906 CVE-2009-3297 Upstream summary: fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount […]

Read more
FreeBSD 12 — linux-seamonkey-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-seamonkey-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — multiple vulnerabilities Related CVEs: CVE-2006-4253 CVE-2006-4340 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4570  +12 more Upstream summary: Mozilla Project reports: MFSA 2009-38: Data corruption with SOCKS5 reply containing DNS […]

Read more
FreeBSD 12 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Several vulnerabilities found in IcedTea-Web Related CVEs: CVE-2012-3422 CVE-2012-3423 Upstream summary: The IcedTea project team reports: CVE-2012-3422: Use of uninitialized instance pointers An uninitialized pointer use flaw was found in […]

Read more
FreeBSD 12 — apr — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — apr — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache APR — DoS vulnerabilities Related CVEs: CVE-2009-0023 CVE-2009-1955 CVE-2009-1956 CVE-2009-3560 CVE-2009-3720 CVE-2010-1623 CVE-2011-0419 CVE-2011-1928 Upstream summary: The Apache Portable Runtime Project reports: Reimplement apr_fnmatch() from scratch using a non-recursive […]

Read more
FreeBSD 12 — openwebmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — openwebmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: "Content-Type" XSS vulnerability affecting other webmail systems Related CVEs: CVE-2004-0519 Upstream summary: Roman Medina-Heigl Hernandez did a survey which other webmail systems where vulnerable to a bug he discovered in […]

Read more
CHAT