chris

IBM AIX 7.2 — CVE-2007-4796 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-4796 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 30 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-4796, IBM Support Bulletin CVE: CVE-2007-4796 NVD summary: Buffer overflow in uucp in bos.net.uucp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors. References: secunia.com/advisories/26715   […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-346-updates — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-346-updates — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2747-1 Related CVEs: CVE-2015-5950 Upstream summary: Dario Weisser discovered that the NVIDIA graphics drivers incorrectly handled certain IOCTL writes. A local attacker could use this issue to possibly gain root […]

Read more
SLES 12 — rtkit — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rtkit — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4326 Upstream summary: RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended […]

Read more
SLES 12 — libgnomesu — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgnomesu — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-1946 Upstream summary: gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid […]

Read more
SLES 12 — cracklib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cracklib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-6318 Upstream summary: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) […]

Read more
CHAT