IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-2007-4236 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-4236 — buffer overflow — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 3 June 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-4236, IBM Support Bulletin CVE: CVE-2007-4236 NVD summary: Buffer overflow in lpd in bos.rte.printers in AIX 5.2 and 5.3 allows local users with printq group privileges to gain root privileges. References: secunia.com/advisories/26219 […]

Read more
Ubuntu 14.04 — bouncycastle — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — bouncycastle — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 June 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3727-1 Related CVEs: CVE-2015-6644 CVE-2015-7940 CVE-2016-1000338 CVE-2016-1000339 CVE-2016-1000341 CVE-2016-1000342 CVE-2016-1000343 CVE-2016-1000345  +1 more Upstream summary: It was discovered that Bouncy Castle incorrectly handled certain crypto algorithms. A remote attacker could […]

Read more
Ubuntu 14.04 — python-keystoneclient — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — python-keystoneclient — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 June 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2705-1 Related CVEs: CVE-2014-7144 CVE-2015-1852 Upstream summary: Qin Zhao discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, […]

Read more
IBM AIX 7.2 — CVE-2008-5384 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2008-5384 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 31 May 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2008-5384, IBM Support Bulletin CVE: CVE-2008-5384 NVD summary: crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor. References: aix.software.ibm.com/aix/efixes/security/aix61_a […]

Read more
IBM AIX 7.2 — CVE-1999-0115 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0115 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 30 May 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0115, IBM PSIRT advisory page CVE: CVE-1999-0115 NVD summary: AIX bugfiler program allows local users to gain root access. References: www.securityfocus.com/bid/1800   www.securityfocus.com/bid/1800 Table of contents Symptom & Impact Environment & Reproduction […]

Read more
Ubuntu 14.04 — linux-lts-utopic — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — linux-lts-utopic — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 May 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3036-1 Related CVEs: CVE-2016-3070 CVE-2016-4482 CVE-2016-4565 CVE-2016-4569 CVE-2016-4578 CVE-2016-4580 CVE-2016-4913 CVE-2016-4997  +12 more Upstream summary: Jan Stancek discovered that the Linux kernel's memory manager did not properly handle moving pages […]

Read more
IBM AIX 7.2 — CVE-1999-0627 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0627 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 24 May 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0627, IBM PSIRT advisory page CVE: CVE-1999-0627 NVD summary: The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of […]

Read more
CHAT