IT, Cloud & DevOps Blog

Ubuntu 16.04 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3063-1 Related CVEs: CVE-2016-5384 Upstream summary: Tobias Stoeckmann discovered that Fontconfig incorrectly handled cache files. A local attacker could possibly use this issue with a specially crafted cache file to […]

Read more
IBM AIX 7.2 — CVE-2016-8981 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2016-8981 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 24 July 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2016-8981, IBM Support Bulletin CVE: CVE-2016-8981 NVD summary: IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. References: www.ibm.com/support/docview.wss?uid=swg21994932   […]

Read more
IBM AIX 7.2 — CVE-2006-0667 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2006-0667 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 18 July 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2006-0667, IBM Support Bulletin CVE: CVE-2006-0667 NVD summary: lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack. References: securitytracker.com/id?1015622   www-1.ibm.com/support/docview.wss?uid=isg1IY7762   www-1.ibm.com/support/docview.wss?uid=isg1IY7763 […]

Read more
Ubuntu 16.04 — bsdiff — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — bsdiff — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4500-1 Related CVEs: CVE-2014-9862 Upstream summary: It was discovered that bsdiff mishandled certain input. If a user were tricked into opening a malicious file, an attacker could cause bsdiff to […]

Read more
CHAT