chris

SLES 12 — libXtst6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXtst6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 October 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2063 Upstream summary: Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — xalan-j2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xalan-j2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 October 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0870-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-0107 Upstream summary: The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote […]

Read more
Ubuntu 14.04 — qt4-x11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — qt4-x11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 October 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2626-1 Related CVEs: CVE-2014-0190 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Upstream summary: Wolfgang Schenk discovered that Qt incorrectly handled certain malformed GIF images. If a user or automated system were tricked into […]

Read more
IBM AIX 7.2 — CVE-2001-1061 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2001-1061 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 19 October 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2001-1061, IBM PSIRT advisory page CVE: CVE-2001-1061 NVD summary: Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error. References: archives.neohapsis.com/archives/aix/2001-q3/0003   archives.neohapsis.com/archives/aix/2001-q3/0003 Table of contents Symptom & […]

Read more
IBM AIX 7.2 — CVE-1999-0101 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0101 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 15 October 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0101, IBM PSIRT advisory page CVE: CVE-1999-0101 NVD summary: Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names. References: ciac.llnl.gov/ciac/bulletins/h-13.shtml   ciac.llnl.gov/ciac/bulletins/h-13.shtml Table of […]

Read more
IBM AIX 7.2 — CVE-1999-0111 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0111 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 15 October 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0111, IBM PSIRT advisory page CVE: CVE-1999-0111 NVD summary: RIP v1 is susceptible to spoofing. References: www.cve.org/CVERecord?id=CVE-1999-0111   www.cve.org/CVERecord?id=CVE-1999-0111 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
CHAT