chris

SLES 12 — libgypsy0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgypsy0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-0523 CVE-2011-0524 Upstream summary: gypsy 0.8 does not properly restrict the files that can be read while running with root privileges, which allows local users […]

Read more
SLES 12 — ppc64-diag — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ppc64-diag — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0928-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-4038 CVE-2014-4039 Upstream summary: ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc […]

Read more
Ubuntu 14.04 — libxrender — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libxrender — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 September 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2568-1 Related CVEs: CVE-2013-7439 Upstream summary: Abhishek Arya discovered that libX11 incorrectly handled memory in the MakeBigReq macro. A remote attacker could use this issue to cause applications to crash, […]

Read more
SLES 12 — python-xdg — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-xdg — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2719-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-1624 Upstream summary: Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to […]

Read more
SLES 12 — libgcab — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgcab — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2015-0552 Upstream summary: Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted […]

Read more
SLES 12 — lighttpd — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lighttpd — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0474-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-2323 CVE-2014-2324 CVE-2013-4508 CVE-2010-0295 CVE-2011-4362 CVE-2012-5533 CVE-2013-4559 CVE-2013-4560  +2 more Upstream summary: SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to […]

Read more
Ubuntu 14.04 — xorg-server-lts-utopic — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — xorg-server-lts-utopic — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2500-1 Related CVEs: CVE-2013-6424 CVE-2015-0255 Upstream summary: Olivier Fourdan discovered that the X.Org X server incorrectly handled XkbSetGeometry requests resulting in an information leak. An attacker able to connect to […]

Read more
SLES 12 — python-pywbem — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-pywbem — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0580-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-6418 Upstream summary: PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an […]

Read more
Ubuntu 14.04 — libyaml-libyaml-perl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libyaml-libyaml-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2461-2 Related CVEs: CVE-2014-9130 Upstream summary: Stanisław Pitucha and Jonathan Gray discovered that libyaml-libyaml-perl did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger […]

Read more
Ubuntu 14.04 — node-semver — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — node-semver — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4776-1 Related CVEs: CVE-2015-8855 Upstream summary: It was discovered that semver incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial of service. Table […]

Read more
CHAT