chris

SLES 15 — slf4j — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — slf4j — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1744-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-8088 Upstream summary: org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData […]

Read more
Ubuntu 14.04 — lcms2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — lcms2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3770-1 Related CVEs: CVE-2016-10165 CVE-2018-16435 CVE-2013-7455 Upstream summary: Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of […]

Read more
SLES 15 — minicom — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — minicom — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1092-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-7467 Upstream summary: A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could […]

Read more
Debian 9 — bchunk — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — bchunk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15953 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — libvorbis — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libvorbis — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 August 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5420-1 Related CVEs: CVE-2017-14160 CVE-2018-10392 CVE-2018-10393 CVE-2018-5146 CVE-2017-14632 CVE-2017-14633 Upstream summary: It was discovered that Vorbis incorrectly handled certain files. An attacker could possibly use this issue to cause a […]

Read more
Debian 9 — golang-1.7 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — golang-1.7 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-7187 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — libspice-server1 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libspice-server1 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0884-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4282 CVE-2015-3247 CVE-2015-5260 CVE-2015-5261 CVE-2016-0749 CVE-2016-2150 CVE-2016-9577 CVE-2016-9578  +1 more Upstream summary: Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows […]

Read more
Debian 9 — prosody — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — prosody — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-18265 CVE-2018-10847 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
Debian 9 — libssh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — libssh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-10933 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — libimobiledevice6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libimobiledevice6 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2142 Upstream summary: userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack […]

Read more
CHAT