IT, Cloud & DevOps Blog

IBM AIX 7.2 — CVE-1999-0023 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0023 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 23 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0023, IBM PSIRT advisory page CVE: CVE-1999-0023 NVD summary: Local user gains root privileges via buffer overflow in rdist, via lookup() function. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom & Impact […]

Read more
IBM AIX 7.2 — CVE-1999-0088 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0088 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 23 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0088, IBM Support Bulletin CVE: CVE-1999-0088 NVD summary: IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. References: www-1.ibm.com/services/brs/brspwhub.nsf/advisori   www-1.ibm.com/services/brs/brspwhub.nsf/advisori Table of contents Symptom & Impact Environment […]

Read more
Ubuntu 14.04 — dpkg — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — dpkg — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2820-1 Related CVEs: CVE-2015-0860 CVE-2015-0840 CVE-2014-3864 CVE-2014-3865 CVE-2014-0471 Upstream summary: Hanno Boeck discovered that the dpkg-deb tool incorrectly handled certain old style Debian binary packages. If a user or an […]

Read more
IBM AIX 7.2 — CVE-2003-0954 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2003-0954 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 22 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2003-0954, IBM Support Bulletin CVE: CVE-2003-0954 NVD summary: Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges. References: secunia.com/advisories/10276/   securitytracker.com/id?1008258   www-1.ibm.com/support/search.wss?rs=0&q=IY48272& Table of […]

Read more
SLES 12 — libmikmod3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmikmod3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 21 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1471-1 (see also SUSE bugzilla) Related CVEs: CVE-2010-2546 CVE-2009-0179 CVE-2009-3995 CVE-2009-3996 CVE-2007-6720 Upstream summary: Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote attackers to execute arbitrary code […]

Read more
SLES 12 — yast2-users — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yast2-users — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1138-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-1601 Upstream summary: yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an […]

Read more
IBM AIX 7.2 — CVE-1999-0129 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0129 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 19 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0129, IBM PSIRT advisory page CVE: CVE-1999-0129 NVD summary: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. References: www.cert.org/advisories/CA-1996-25.html   www.cert.org/advisories/CA-1996-25.html […]

Read more
IBM AIX 7.2 — CVE-1999-0091 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0091 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 19 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0091, IBM PSIRT advisory page CVE: CVE-1999-0091 NVD summary: Buffer overflow in AIX writesrv command allows local users to obtain root access. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom & Impact […]

Read more
SLES 12 — libmodplug1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmodplug1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2011:0943-1 (see also SUSE bugzilla) Related CVEs: CVE-2011-1761 CVE-2013-4233 CVE-2013-4234 Upstream summary: Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote […]

Read more
CHAT