IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-1999-0093 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0093 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 1 January 2017 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0093, IBM PSIRT advisory page CVE: CVE-1999-0093 NVD summary: AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom […]

Read more
SLES 12 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1926-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4566 CVE-2015-5244 CVE-2016-3099 Upstream summary: mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting […]

Read more
IBM AIX 7.2 — CVE-2002-0744 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2002-0744 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 30 December 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2002-0744, IBM PSIRT advisory page CVE: CVE-2002-0744 NVD summary: namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. References: archives.neohapsis.com/archives/aix/2002-q2/0005 […]

Read more
Ubuntu 16.04 — ubuntu-release-upgrader — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ubuntu-release-upgrader — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3623-1 Related CVEs: https://launchpad.net/bugs/1174007 Upstream summary: It was discovered that ubuntu-release-upgrader did not correctly drop permissions before opening a browser to view the release notes. This update fixes the issue. […]

Read more
IBM AIX 7.1 — CVE-2016-3053 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2016-3053 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 23 December 2016 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2016-3053, IBM Support Bulletin CVE: CVE-2016-3053 NVD summary: IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. References: aix.software.ibm.com/aix/efixes/security/lsmcode   www.securityfocus.com/bid/93605   www.securitytracker.com/id/1037030 […]

Read more
CHAT