IT, Cloud & DevOps Blog

Ubuntu 14.04 — qtbase-opensource-src — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — qtbase-opensource-src — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2626-1 Related CVEs: CVE-2014-0190 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Upstream summary: Wolfgang Schenk discovered that Qt incorrectly handled certain malformed GIF images. If a user or automated system were tricked into […]

Read more
SLES 12 — ruby2.1-rubygem-bundler — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-bundler — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0795-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-0334 Upstream summary: Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with […]

Read more
SLES 12 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:015 (see also SUSE bugzilla) Related CVEs: CVE-2010-0407 CVE-2010-4531 CVE-2016-10109 Upstream summary: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite […]

Read more
IBM AIX 7.2 — CVE-2006-4254 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2006-4254 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 13 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2006-4254, IBM Support Bulletin CVE: CVE-2006-4254 NVD summary: Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors. References: ftp://aix.software.ibm.com/aix/efixes/security/R   secunia.com/advisories/21541   […]

Read more
IBM AIX 7.2 — CVE-2006-1247 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2006-1247 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 11 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2006-1247, IBM Support Bulletin CVE: CVE-2006-1247 NVD summary: rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. References: secunia.com/advisories/19656 […]

Read more
IBM AIX 7.2 — CVE-1999-0010 — denial of service — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0010 — denial of service — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 10 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0010, IBM PSIRT advisory page CVE: CVE-1999-0010 NVD summary: Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. References: ftp://patches.sgi.com/support/free/security/advi   www1.itrc.hp.com/service/cki/docDisplay.do?docId   ftp://patches.sgi.com/support/free/security/advi Table of contents Symptom […]

Read more
IBM AIX 7.2 — CVE-1999-0118 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0118 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 10 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0118, IBM PSIRT advisory page CVE: CVE-1999-0118 NVD summary: AIX infod allows local users to gain root access through an X display. References: marc.info/?l=bugtraq&m=91158980826979&w=2   marc.info/?l=bugtraq&m=91158980826979&w=2 Table of contents Symptom & Impact […]

Read more
SLES 12 — libopenssl0_9_8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopenssl0_9_8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:020 (see also SUSE bugzilla) Related CVEs: CVE-2009-3245 CVE-2009-4355 CVE-2009-5146 CVE-2010-4180 CVE-2010-4252 CVE-2011-4109 CVE-2011-4354 CVE-2011-5095  +4 more Upstream summary: OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand […]

Read more
CHAT