chris

Ubuntu 16.04 — pyopenssl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — pyopenssl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 August 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3813-1 Related CVEs: CVE-2018-1000807 CVE-2018-1000808 Upstream summary: It was discovered that pyOpenSSL incorrectly handled memory when handling X509 objects. A remote attacker could use this issue to cause pyOpenSSL to […]

Read more
SLES 15 — libXxf86dga1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libXxf86dga1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1991 CVE-2013-2000 Upstream summary: Multiple integer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to trigger allocation of insufficient memory and a buffer […]

Read more
Debian 9 — packagekit — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — packagekit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-1106 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — perl-Tk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-Tk — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2006:052 (see also SUSE bugzilla) Related CVEs: CVE-2006-4484 Upstream summary: Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an […]

Read more
Ubuntu 16.04 — passenger — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — passenger — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 August 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5261-1 Related CVEs: CVE-2017-16355 CVE-2018-12029 Upstream summary: It was discovered that Phusion Passenger incorrectly handled a file path in the application root folder. An attacker could possibly use this issue […]

Read more
Debian 9 — bird — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — bird — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
SLES 15 — libXp6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libXp6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1102-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2062 Upstream summary: Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
SLES 15 — libXext6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libXext6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 July 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1099-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1982 Upstream summary: Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
SLES 12 — libvorbis0 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvorbis0 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 July 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:012 (see also SUSE bugzilla) Related CVEs: CVE-2008-1420 CVE-2009-3379 CVE-2012-0444 CVE-2017-14160 CVE-2017-14632 CVE-2017-14633 CVE-2018-10392 CVE-2018-10393  +1 more Upstream summary: Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 […]

Read more
CHAT