IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-2005-4271 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2005-4271 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 12 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2005-4271, IBM Support Bulletin CVE: CVE-2005-4271 NVD summary: Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code. References: secunia.com/advisories/18088   www-1.ibm.com/support/search.wss?rs=0&q=IY78227&   www.securityfocus.com/archive/1/419577/100/0/thr […]

Read more
Ubuntu 14.04 — apparmor — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — apparmor — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3784-1 Related CVEs: https://launchpad.net/bugs/1788929 https://launchpad.net/bugs/1794848 CVE-2017-6507 CVE-2014-1424 Upstream summary: As a security improvement, this update adjusts the private-files abstraction to disallow writing to thumbnailer configuration files. Additionally adjust the private-files, […]

Read more
Ubuntu 14.04 — augeas — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — augeas — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3400-1 Related CVEs: CVE-2017-7555 Upstream summary: It was discovered that Augeas incorrectly handled certain strings. An attacker could use this issue to cause Augeas to crash, leading to a denial […]

Read more
SLES 12 — yodl — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yodl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1504-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10375 Upstream summary: Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
Ubuntu 16.04 — libpam-radius-auth — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libpam-radius-auth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 March 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4290-1 Related CVEs: CVE-2015-9542 Upstream summary: It was discovered that libpam-radius-auth incorrectly handled certain long passwords. A remote attacker could possibly use this issue to cause libpam-radius-auth to crash, resulting […]

Read more
Ubuntu 14.04 — game-music-emu — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — game-music-emu — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4816-1 Related CVEs: CVE-2017-17446 Upstream summary: It was discovered that game-music-emu mishandled certain crafted input. A remote attacker could use this vulnerability to cause game-music-emu to crash. Table of contents […]

Read more
CHAT