chris

SLES 12 — logrotate — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — logrotate — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:010 (see also SUSE bugzilla) Related CVEs: CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 Upstream summary: Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data […]

Read more
IBM AIX 7.2 — CVE-2005-4273 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2005-4273 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 21 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2005-4273, IBM PSIRT advisory page CVE: CVE-2005-4273 NVD summary: Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files. References: secunia.com/advisories/18088 […]

Read more
IBM AIX 7.2 — CVE-2002-0746 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2002-0746 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 21 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2002-0746, IBM PSIRT advisory page CVE: CVE-2002-0746 NVD summary: Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument. References: archives.neohapsis.com/archives/aix/2002-q2/0005   archives.neohapsis.com/archives/aix/2002-q2/0005 Table of contents Symptom & Impact Environment […]

Read more
SLES 12 — zoo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — zoo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2006:005 (see also SUSE bugzilla) Related CVEs: CVE-2006-0855 CVE-2007-1669 Upstream summary: Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda […]

Read more
IBM AIX 7.2 — CVE-2001-1095 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2001-1095 — buffer overflow — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 16 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2001-1095, IBM Support Bulletin CVE: CVE-2001-1095 NVD summary: Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter. References: archives.neohapsis.com/archives/aix/2001-q4/0000   www-1.ibm.com/support/search.wss?rs=0&q=IY24231& […]

Read more
Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 November 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4290-2 Related CVEs: CVE-2015-9542 Upstream summary: USN-4290-1 fixed a vulnerability in libpam-radius-auth. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It […]

Read more
SLES 12 — libXxf86vm1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXxf86vm1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2001 Upstream summary: Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary […]

Read more
CHAT