chris

FreeBSD 12 — potrace — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — potrace — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: potrace — multiple memory failure Related CVEs: CVE-2016-8685 CVE-2016-8686 Upstream summary: potrace reports: CVE-2016-8685: invalid memory access in findnext CVE-2016-8686: memory allocation failure Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — duo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — duo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: duo — Two-factor authentication bypass Upstream summary: The duo security team reports: An untrusted user may be able to set the http_proxy variable to an invalid address. If this happens, […]

Read more
FreeBSD 12 — rubygem-geminabox — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-geminabox — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-geminabox — XSS vulnerabilities Related CVEs: CVE-2017-14506 CVE-2017-14683 CVE-2017-16792 Upstream summary: NVD reports: Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject […]

Read more
FreeBSD 12 — compat5x-amd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — compat5x-amd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-10860 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2010-2529 Upstream summary: Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of […]

Read more
FreeBSD 12 — mariadb-server — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb-server — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL – Multiple vulnerabilities Related CVEs: CVE-2012-4414 CVE-2012-5611 CVE-2012-5612 CVE-2012-5615 CVE-2012-5627 CVE-2015-4792 CVE-2015-4802 CVE-2015-4807  +8 more Upstream summary: Oracle reports: Critical Patch Update: MySQL Server, version(s) 5.5.45 and prior, 5.6.26 […]

Read more
FreeBSD 12 — php56-wddx — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-wddx — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-8383 CVE-2015-8386 CVE-2015-8387 CVE-2015-8389 CVE-2015-8390 CVE-2015-8391 CVE-2015-8393 CVE-2015-8394  +10 more Upstream summary: The PHP Group reports: Please reference CVE/URL list for details Table of […]

Read more
FreeBSD 12 — sl-openoffice-SL — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sl-openoffice-SL — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading a […]

Read more
Ubuntu 14.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 December 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4229-1 Related CVEs: CVE-2018-12327 CVE-2018-7182 CVE-2018-7183 CVE-2018-7184 CVE-2018-7185 CVE-2016-2519 CVE-2016-7426 CVE-2016-7427  +12 more Upstream summary: It was discovered that ntpq and ntpdc incorrectly handled some arguments. An attacker could possibly […]

Read more
CHAT