IT, Cloud & DevOps Blog

Ubuntu 16.04 — nova-lxd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nova-lxd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 March 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3195-1 Related CVEs: CVE-2017-5936 https://launchpad.net/bugs/1656847 Upstream summary: James Page discovered that Nova-LXD incorrectly set up virtual network devices when creating LXD instances. This could result in an unintended firewall configuration. […]

Read more
SLES 12 — ed — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ed — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:14005-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5357 Upstream summary: regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an […]

Read more
IBM AIX 7.2 — CVE-2002-1690 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2002-1690 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 20 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2002-1690, IBM PSIRT advisory page CVE: CVE-2002-1690 NVD summary: Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225. References: archives.neohapsis.com/archives/aix/2002-q1/0005 […]

Read more
IBM AIX 7.2 — CVE-2009-2727 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2009-2727 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 18 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2009-2727, IBM Support Bulletin CVE: CVE-2009-2727 NVD summary: Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, […]

Read more
Ubuntu 16.04 — libxrender — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libxrender — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 March 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5436-1 Related CVEs: CVE-2016-7949 CVE-2016-7950 Upstream summary: Tobias Stoeckmann discovered that libXrender incorrectly handled certain responses. An attacker could possibly use this issue to cause a denial of service, or […]

Read more
IBM AIX 7.2 — CVE-2010-0961 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2010-0961 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 17 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2010-0961, IBM Support Bulletin CVE: CVE-2010-0961 NVD summary: Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors. References: aix.software.ibm.com/aix/efixes/security/qoslist […]

Read more
Ubuntu 14.04 — emacs24 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — emacs24 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3427-1 Related CVEs: CVE-2017-14482 Upstream summary: Charles A. Roelli discovered that Emacs incorrectly handled certain files. If a user were tricked into opening a specially crafted file (e.g., email messages […]

Read more
Ubuntu 14.04 — lxc — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — lxc — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3375-1 Related CVEs: CVE-2016-10124 CVE-2017-5985 CVE-2016-8649 https://launchpad.net/bugs/1501491 https://launchpad.net/bugs/1501310 CVE-2015-1335 CVE-2015-1331 CVE-2015-1334 Upstream summary: It was discovered that LXC incorrectly handled the TIOCSTI ioctl. An attacker could possibly use this issue […]

Read more
CHAT