IT, Cloud & DevOps Blog

Ubuntu 16.04 — sniffit — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — sniffit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 April 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4652-1 Related CVEs: CVE-2014-5439 Upstream summary: It was discovered that SniffIt incorrectly handled certain configuration files. An attacker could possibly use this issue to execute arbitrary code. Table of contents […]

Read more
IBM AIX 7.2 — CVE-1999-0687 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0687 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 25 April 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0687, IBM PSIRT advisory page CVE: CVE-1999-0687 NVD summary: The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. References: sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   www.ciac.org/ciac/bulletins/k-001.shtml   www.securityfocus.com/bid/637 Table […]

Read more
SLES 12 — libsilc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsilc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:006 (see also SUSE bugzilla) Related CVEs: CVE-2008-1227 Upstream summary: Stack-based buffer overflow in the silc_fingerprint function in lib/silcutil/silcutil.c in Secure Internet Live Conferencing (SILC) Toolkit 1.1.5, and unspecified earlier versions, allows […]

Read more
SLES 12 — libpulse0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpulse0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0999-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3970 Upstream summary: The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of […]

Read more
IBM AIX 7.2 — CVE-2002-0679 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2002-0679 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 23 April 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2002-0679, IBM Support Bulletin CVE: CVE-2002-0679 NVD summary: Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the […]

Read more
IBM AIX 7.2 — CVE-1999-1119 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-1119 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 22 April 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-1119, IBM PSIRT advisory page CVE: CVE-1999-1119 NVD summary: FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands. References: www.cert.org/advisories/CA-1992-09.html   www.securityfocus.com/bid/41   […]

Read more
Ubuntu 14.04 — cups-filters — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — cups-filters — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2838-1 Related CVEs: CVE-2015-8560 CVE-2015-8327 CVE-2015-3258 CVE-2015-3279 CVE-2015-2265 CVE-2014-2707 Upstream summary: Adam Chester discovered that the cups-filters foomatic-rip filter incorrectly stripped shell escape characters. A remote attacker could possibly use […]

Read more
CHAT