IT, Cloud & DevOps Blog

Ubuntu 14.04 — libidn2-0 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libidn2-0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3421-2 Related CVEs: CVE-2017-14062 Upstream summary: USN-3421-1 fixed a vulnerability in Libidn2. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Table of contents Symptom […]

Read more
Ubuntu 16.04 — libsamplerate — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libsamplerate — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 January 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5749-1 Related CVEs: CVE-2017-7697 Upstream summary: Erik de Castro Lopo and Agostino Sarubbo discovered that libsamplerate did not properly perform bounds checking. If a user were tricked into processing a […]

Read more
Ubuntu 16.04 — openssl-ibmca — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — openssl-ibmca — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6046-1 Related CVEs: https://launchpad.net/bugs/2015454 Upstream summary: It was discovered that OpenSSL-ibmca incorrectly handled certain RSA decryption. An attacker could possibly use this issue to expose sensitive information. Table of contents […]

Read more
IBM AIX 7.2 — CVE-2007-2995 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-2995 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 14 January 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-2995, IBM Support Bulletin CVE: CVE-2007-2995 NVD summary: Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors. References: osvdb.org/36741   secunia.com/advisories/25458   www-1.ibm.com/support/docview.wss?uid=isg1IY9552 Table of […]

Read more
SLES 12 — libical1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libical1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1989-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5824 CVE-2016-5827 CVE-2016-9584 Upstream summary: libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. Table of contents […]

Read more
CHAT