IT, Cloud & DevOps Blog

SLES 12 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1283-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-6272 CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 Upstream summary: Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta […]

Read more
Ubuntu 16.04 — harfbuzz — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — harfbuzz — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 January 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5746-1 Related CVEs: CVE-2015-9274 CVE-2015-8947 CVE-2016-2052 Upstream summary: Behzad Najjarpour Jabbari discovered that HarfBuzz incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial […]

Read more
Ubuntu 14.04 — eog — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — eog — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3069-1 Related CVEs: CVE-2016-6855 CVE-2013-7447 Upstream summary: It was discovered that Eye of GNOME incorrectly handled certain invalid UTF-8 strings. If a user were tricked into opening a specially-crafted image, […]

Read more
IBM AIX 7.2 — CVE-1999-0131 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0131 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 3 January 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0131, IBM PSIRT advisory page CVE: CVE-1999-0131 NVD summary: Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. References: www.securityfocus.com/bid/717   […]

Read more
CHAT