IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-2002-0790 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2002-0790 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 10 March 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2002-0790, IBM Support Bulletin CVE: CVE-2002-0790 NVD summary: clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges. References: techsupport.services.ibm.com/server/aix.uhuic_ge   […]

Read more
SLES 12 — xfsprogs — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xfsprogs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2383-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2150 Upstream summary: xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a […]

Read more
Ubuntu 14.04 — mono — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — mono — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2547-1 Related CVEs: CVE-2011-0992 CVE-2012-3543 CVE-2015-2318 CVE-2015-2319 CVE-2015-2320 Upstream summary: It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use […]

Read more
SLES 12 — pam-modules — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam-modules — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1760-1 (see also SUSE bugzilla) Related CVEs: CVE-2011-3172 Upstream summary: A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are […]

Read more
Ubuntu 14.04 — node-minimatch — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — node-minimatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4783-1 Related CVEs: CVE-2016-10540 Upstream summary: It was discovered that minimatch did not perform necessary bounds checking on regular expressions. An attacker could use this vulnerability to cause a denial […]

Read more
CHAT