IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-2005-3060 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2005-3060 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 6 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2005-3060, IBM Support Bulletin CVE: CVE-2005-3060 NVD summary: Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors. References: secunia.com/advisories/16996   securitytracker.com/id?1014991 […]

Read more
IBM AIX 7.2 — CVE-1999-0055 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0055 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 5 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0055, IBM Support Bulletin CVE: CVE-1999-0055 NVD summary: Buffer overflows in Sun libnsl allow root access. References: sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   www-1.ibm.com/support/search.wss?rs=0&q=IX80543&   sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
IBM AIX 7.2 — CVE-1999-0789 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0789 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 5 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0789, IBM PSIRT advisory page CVE: CVE-1999-0789 NVD summary: Buffer overflow in AIX ftpd in the libc library. References: www.ciac.org/ciac/bulletins/j-072.shtml   www.securityfocus.com/bid/679   www.ciac.org/ciac/bulletins/j-072.shtml Table of contents Symptom & Impact Environment & […]

Read more
Ubuntu 14.04 — jasper — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — jasper — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3693-1 Related CVEs: CVE-2015-5203 CVE-2015-5221 CVE-2016-10248 CVE-2016-10250 CVE-2016-8883 CVE-2016-8887 CVE-2016-9262 CVE-2016-9387  +12 more Upstream summary: It was discovered that JasPer incorrectly handled certain malformed JPEG-2000 image files. If a user […]

Read more
IBM AIX 7.2 — CVE-2006-5005 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2006-5005 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 3 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2006-5005, IBM Support Bulletin CVE: CVE-2006-5005 NVD summary: Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login. References: ftp://aix.software.ibm.com/aix/efixes/security/R […]

Read more
SLES 12 — hexchat — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hexchat — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2872-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2087 Upstream summary: Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. […]

Read more
IBM AIX 7.2 — CVE-1999-0130 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0130 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 1 March 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0130, IBM PSIRT advisory page CVE: CVE-1999-0130 NVD summary: Local users can start Sendmail in daemon mode and gain root privileges. References: www.securityfocus.com/bid/716   www.securityfocus.com/bid/716 Table of contents Symptom & Impact Environment […]

Read more
Ubuntu 14.04 — gtk-vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — gtk-vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3203-1 Related CVEs: CVE-2017-5884 CVE-2017-5885 Upstream summary: It was discovered that gtk-vnc incorrectly validated certain data. A malicious server could use this issue to cause gtk-vnc to crash, resulting in […]

Read more
SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2923-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-15638 Upstream summary: The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 […]

Read more
CHAT