IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-2008-2163 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2008-2163 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 8 April 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2008-2163, IBM Support Bulletin CVE: CVE-2008-2163 NVD summary: Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote […]

Read more
Ubuntu 14.04 — swift — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — swift — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3451-1 Related CVEs: CVE-2015-5223 CVE-2016-0737 CVE-2016-0738 CVE-2014-7960 CVE-2015-1856 CVE-2014-3497 Upstream summary: It was discovered that OpenStack Swift incorrectly handled tempurls. A remote authenticated user in possession of a tempurl key […]

Read more
Ubuntu 14.04 — xdg-utils — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — xdg-utils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 April 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3650-1 Related CVEs: CVE-2017-18266 Upstream summary: It was discovered that xdg-utils incorrectly handled certain inputs. An attacker could possibly use this to execute arbitrary code. Table of contents Symptom & […]

Read more
Ubuntu 16.04 — nvidia-graphics-drivers-367 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nvidia-graphics-drivers-367 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 April 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3122-1 Related CVEs: CVE-2016-7382 CVE-2016-7389 Upstream summary: It was discovered that the NVIDIA graphics drivers incorrectly sanitized user mode inputs. A local attacker could use this issue to possibly gain […]

Read more
SLES 12 — php7 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php7 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 April 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0534-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5340 CVE-2016-10162 CVE-2016-7133 CVE-2016-7479 CVE-2016-7480 CVE-2016-9138 CVE-2016-9936 CVE-2017-11142  +6 more Upstream summary: Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that […]

Read more
IBM AIX 7.2 — CVE-2007-0978 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-0978 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 3 April 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-0978, IBM Support Bulletin CVE: CVE-2007-0978 NVD summary: Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data. References: osvdb.org/33200   secunia.com/advisories/24154   www-1.ibm.com/support/docview.wss?uid=isg1IY9490 […]

Read more
SLES 12 — cvs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cvs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 31 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0311-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-0804 CVE-2017-12836 Upstream summary: Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause […]

Read more
IBM AIX 7.2 — CVE-1999-0113 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0113 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 30 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0113, IBM PSIRT advisory page CVE: CVE-1999-0113 NVD summary: Some implementations of rlogin allow root access if given a -froot parameter. References: www.securityfocus.com/bid/458   www.securityfocus.com/bid/458 Table of contents Symptom & Impact Environment […]

Read more
IBM AIX 7.2 — CVE-1999-0128 — denial of service — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0128 — denial of service — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 29 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0128, IBM PSIRT advisory page CVE: CVE-1999-0128 NVD summary: Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom […]

Read more
CHAT