IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-1999-0024 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0024 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 19 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0024, IBM PSIRT advisory page CVE: CVE-1999-0024 NVD summary: DNS cache poisoning via BIND, by predictable query IDs. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
IBM AIX 7.2 — CVE-2007-4355 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-4355 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 18 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-4355, IBM Support Bulletin CVE: CVE-2007-4355 NVD summary: Buffer overflow in the at program on IBM AIX 5.3 allows local users to gain privileges via unspecified vectors. References: ftp://aix.software.ibm.com/aix/efixes/security/R   osvdb.org/36794   […]

Read more
SLES 12 — coolkey — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — coolkey — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2007-4129 Upstream summary: CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory. Table of […]

Read more
SLES 12 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 15 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2058-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7705 CVE-2015-7853 CVE-2015-7871 CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 CVE-2014-9297  +12 more Upstream summary: The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 […]

Read more
Ubuntu 14.04 — rabbitmq-server — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — rabbitmq-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3374-1 Related CVEs: CVE-2016-9877 Upstream summary: It was discovered that RabbitMQ incorrectly handled MQTT (MQ Telemetry Transport) authentication. A remote attacker could use this issue to authenticate successfully with an […]

Read more
SLES 12 — libXv1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXv1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1104-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1989 CVE-2013-2066 Upstream summary: Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer […]

Read more
IBM AIX 7.2 — CVE-2007-6232 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2007-6232 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 12 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2007-6232, IBM PSIRT advisory page CVE: CVE-2007-6232 NVD summary: Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error […]

Read more
IBM AIX 7.2 — CVE-2004-1330 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2004-1330 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 12 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2004-1330, IBM Support Bulletin CVE: CVE-2004-1330 NVD summary: Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username. References: marc.info/?l=bugtraq&m=110355931920123&w=2   www-1.ibm.com/support/search.wss?rs=0&q=IY64312& […]

Read more
CHAT