chris

Debian 9 — batik — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — batik — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5662 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 18.04 — cinnamon — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — cinnamon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4844-1 Related CVEs: CVE-2018-13054 Upstream summary: Matthias Gerstner discovered that the cinnamon-settings-users utility in Cinnamon did not safely handle symlinks. An unprivileged attacker could potentially use this vulnerability to overwrite […]

Read more
Debian 9 — gnupg1 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — gnupg1 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-12020 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 9 — irssi — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — irssi — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15227 CVE-2017-9468 CVE-2018-5205 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification […]

Read more
Debian 9 — aodh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — aodh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-12440 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 14.04 — fop — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — fop — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3281-1 Related CVEs: CVE-2017-5661 Upstream summary: Pierre Ernst discovered that Apache Fop incorrectly handled XML external entities. A remote attacker could possibly use this issue to obtain sensitive files from […]

Read more
Ubuntu 16.04 — flask — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — flask — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 June 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4378-1 Related CVEs: CVE-2018-1000656 Upstream summary: It was discovered that Flask incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. Table of […]

Read more
Ubuntu 14.04 — mini-httpd — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — mini-httpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4848-1 Related CVEs: CVE-2018-18778 Upstream summary: It was discovered that ACME mini_httpd did not properly handle HTTP GET requests with empty headers. A remote attacker could use this vulnerability to […]

Read more
SLES 12 — pam_yubico — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_yubico — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 June 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2018-9275 Upstream summary: In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the […]

Read more
CHAT