chris

IBM AIX 7.2 — CVE-1999-0048 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0048 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 14 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0048, IBM PSIRT advisory page CVE: CVE-1999-0048 NVD summary: Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. References: sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col Table of contents […]

Read more
IBM AIX 7.2 — CVE-2009-1355 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2009-1355 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 11 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2009-1355, IBM Support Bulletin CVE: CVE-2009-1355 NVD summary: Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename. References: aix.software.ibm.com/aix/efixes/security/muxatmd […]

Read more
Ubuntu 14.04 — webkitgtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — webkitgtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 November 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2937-1 Related CVEs: CVE-2014-1748 CVE-2015-1071 CVE-2015-1076 CVE-2015-1081 CVE-2015-1083 CVE-2015-1120 CVE-2015-1122 CVE-2015-1127  +12 more Upstream summary: A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. […]

Read more
SLES 12 — gzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:008 (see also SUSE bugzilla) Related CVEs: CVE-2010-0001 CVE-2009-2624 Upstream summary: Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably […]

Read more
IBM AIX 7.2 — CVE-2015-9281 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2015-9281 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 8 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2015-9281, IBM PSIRT advisory page CVE: CVE-2015-9281 NVD summary: Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. References: support.sas.com/kb/55/537.html   support.sas.com/kb/55/537.html Table of contents […]

Read more
IBM AIX 7.2 — CVE-1999-0318 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0318 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 6 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0318, IBM PSIRT advisory page CVE: CVE-1999-0318 NVD summary: Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom […]

Read more
SLES 12 — kernel-xen — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kernel-xen — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2009:061 (see also SUSE bugzilla) Related CVEs: CVE-2009-3939 CVE-2009-4536 CVE-2010-3081 CVE-2010-3301 CVE-2010-3310 CVE-2013-2850 CVE-2014-0131 CVE-2014-4608  +12 more Upstream summary: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and […]

Read more
CHAT