chris

FreeBSD 12 — ktorrent-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ktorrent-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ktorrent — multiple vulnerabilities Related CVEs: CVE-2007-1384 CVE-2007-1385 Upstream summary: Two problems have been found in KTorrent: KTorrent does not properly sanitize file names to filter out ".." components, so […]

Read more
FreeBSD 12 — py27-rsa — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-rsa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-rsa — Bleichenbacher'06 signature forgery vulnerability Related CVEs: CVE-2016-1494 Upstream summary: Filippo Valsorda reports: python-rsa is vulnerable to a straightforward variant of the Bleichenbacher'06 attack against RSA signature verification with […]

Read more
FreeBSD 12 — transmission-deamon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — transmission-deamon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libutp — remote denial of service or arbitrary code execution Related CVEs: CVE-2012-6129 Upstream summary: NVD reports: Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 […]

Read more
FreeBSD 12 — opengtl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — opengtl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
FreeBSD 12 — citadel — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — citadel — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fd_set — bitmap index overflow in multiple applications Upstream summary: 3APA3A reports: If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory […]

Read more
Ubuntu 18.04 — libcgroup — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libcgroup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4845-1 Related CVEs: CVE-2018-14348 Upstream summary: It was discovered that libcgroup incorrectly handled log file permissions. An attacker could possibly use this issue to obtain sensitive information. Table of contents […]

Read more
SLES 15 — postgresql — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — postgresql — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3107-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14798 Upstream summary: A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their […]

Read more
FreeBSD 12 — mozilla-thunderbird — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mozilla-thunderbird — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — multiple vulnerabilities Related CVEs: CAN-2006-0884 CVE-2004-0762 CVE-2004-0765 CVE-2004-0904 CVE-2004-0905 CVE-2004-0908 CVE-2004-0909 CVE-2004-1156  +12 more Upstream summary: The Mozilla Foundation reports of multiple security issues in Firefox, Seamonkey, and […]

Read more
FreeBSD 12 — atutor — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — atutor — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: atutor — multiple vulnerabilities Upstream summary: ATutor reports: Security Fixes: Added a new layer of security over all php superglobals, fixed several XSS, CSRF, and SQL injection vulnerabilities. Table of […]

Read more
Debian 9 — keystone — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — keystone — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-14432 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT