chris

Ubuntu 14.04 — optipng — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — optipng — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3495-1 Related CVEs: CVE-2017-1000229 CVE-2015-7801 CVE-2015-7802 CVE-2016-2191 CVE-2016-3981 CVE-2016-3982 Upstream summary: It was discovered that OptiPNG incorrectly handled memory. A remote attacker could use this issue with a specially crafted […]

Read more
Ubuntu 18.04 — network-manager — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — network-manager — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3807-1 Related CVEs: CVE-2018-15688 Upstream summary: Felix Wilhelm discovered that the NetworkManager internal DHCPv6 client incorrectly handled certain DHCPv6 messages. In non-default configurations where the internal DHCP client is enabled, […]

Read more
Debian 9 — tiff — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — tiff — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-9936 CVE-2017-9935 CVE-2017-11613 CVE-2018-12900 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches […]

Read more
Debian 9 — gimp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — gimp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-17784 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 14.04 — nasm — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nasm — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3694-1 Related CVEs: CVE-2017-10686 CVE-2017-11111 CVE-2017-14228 CVE-2017-17810 CVE-2017-17811 CVE-2017-17812 CVE-2017-17813 CVE-2017-17814  +7 more Upstream summary: It was discovered that NASM incorrectly handled certain source files. If a user or automated […]

Read more
Ubuntu 14.04 — lame — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — lame — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4780-1 Related CVEs: CVE-2015-9099 CVE-2015-9100 CVE-2015-9101 CVE-2017-13712 CVE-2017-15018 CVE-2017-11720 CVE-2017-9411 CVE-2017-8419  +4 more Upstream summary: It was discovered that LAME incorrectly handled certain audio files. A remote attacker could possibly […]

Read more
Debian 9 — nova — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — nova — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 June 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-16239 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — gccgo-6 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gccgo-6 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 June 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5770-1 Related CVEs: CVE-2017-11671 Upstream summary: Todd Eisenberger discovered that certain versions of GNU Compiler Collection (GCC) could be made to clobber the status flag of RDRAND and RDSEED with […]

Read more
Ubuntu 14.04 — ldns — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — ldns — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 June 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3491-1 Related CVEs: CVE-2014-3209 CVE-2017-1000231 CVE-2017-1000232 Upstream summary: Leon Weber discovered that the ldns-keygen tool incorrectly set permissions on private keys. A local attacker could possibly use this issue to […]

Read more
CHAT