IT, Cloud & DevOps Blog

SLES 12 — libnm0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libnm0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 April 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2015-2924 CVE-2016-0764 Upstream summary: The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote […]

Read more
Ubuntu 14.04 — oxide-qt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — oxide-qt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3236-1 Related CVEs: CVE-2017-5029 CVE-2017-5030 CVE-2017-5031 CVE-2017-5033 CVE-2017-5035 CVE-2017-5037 CVE-2017-5040 CVE-2017-5041  +12 more Upstream summary: Multiple vulnerabilities were discovered in Chromium. If a user were tricked in to opening a […]

Read more
SLES 12 — ruby2.1-rubygem-yard — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-yard — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-17042 Upstream summary: lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to […]

Read more
Ubuntu 16.04 — pcsc-lite — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — pcsc-lite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3176-1 Related CVEs: CVE-2016-10109 Upstream summary: Peter Wu discovered that the PC/SC service did not correctly handle certain resources. A local attacker could use this issue to cause PC/SC to […]

Read more
Ubuntu 14.04 — nagios3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nagios3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3253-2 Related CVEs: https://launchpad.net/bugs/1690380 CVE-2013-7108 CVE-2013-7205 CVE-2014-1878 CVE-2016-9566 Upstream summary: USN-3253-1 fixed vulnerabilities in Nagios. The update prevented log files from being displayed in the web interface. This update fixes […]

Read more
IBM AIX 7.2 — CVE-2016-8967 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2016-8967 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 11 April 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2016-8967, IBM Support Bulletin CVE: CVE-2016-8967 NVD summary: IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user. References: www.ibm.com/support/docview.wss?uid=swg21995019   […]

Read more
Ubuntu 16.04 — xmlsec1 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — xmlsec1 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 April 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5674-1 Related CVEs: CVE-2017-1000061 Upstream summary: It was discovered that XML Security Library incorrectly handled certain input documents. An attacker could possibly use this issue to obtain sensitive information or […]

Read more
Ubuntu 14.04 — libxml-libxml-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libxml-libxml-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3494-1 Related CVEs: CVE-2017-10672 CVE-2015-3451 Upstream summary: It was discovered that XML::LibXML incorrectly handled memory when processing a replaceChild call. A remote attacker could possibly use this issue to execute […]

Read more
Ubuntu 14.04 — xorg-server-lts-xenial — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — xorg-server-lts-xenial — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3456-1 Related CVEs: CVE-2017-12176 CVE-2017-12177 CVE-2017-12178 CVE-2017-12179 CVE-2017-12180 CVE-2017-12181 CVE-2017-12182 CVE-2017-12183  +9 more Upstream summary: It was discovered that the X.Org X server incorrectly handled certain lengths. An attacker able […]

Read more
IBM AIX 7.2 — CVE-1999-0089 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0089 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 8 April 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0089, IBM PSIRT advisory page CVE: CVE-1999-0089 NVD summary: Buffer overflow in AIX libDtSvc library can allow local users to gain root access. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom & […]

Read more
CHAT