IT, Cloud & DevOps Blog

SLES 12 — libspice-server1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libspice-server1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0884-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4282 CVE-2015-3247 CVE-2015-5260 CVE-2015-5261 CVE-2016-0749 CVE-2016-2150 CVE-2016-9577 CVE-2016-9578  +3 more Upstream summary: Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows […]

Read more
SLES 12 — obs-service-source_validator — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — obs-service-source_validator — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1839-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-4007 Upstream summary: Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to […]

Read more
Ubuntu 14.04 — hplip — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — hplip — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2699-1 Related CVEs: CVE-2015-0839 Upstream summary: Enrico Zini discovered that HPLIP used a short GPG key ID when downloading keys from the keyserver. An attacker could possibly use this to […]

Read more
IBM AIX 7.2 — CVE-1999-0017 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0017 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 5 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0017, IBM PSIRT advisory page CVE: CVE-1999-0017 NVD summary: FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE […]

Read more
IBM AIX 7.2 — CVE-2008-5387 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2008-5387 — buffer overflow — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 5 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2008-5387, IBM Support Bulletin CVE: CVE-2008-5387 NVD summary: Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain […]

Read more
SLES 12 — lua — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lua — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-5461 Upstream summary: Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial […]

Read more
IBM AIX 7.2 — CVE-1999-0009 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0009 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 4 February 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0009, IBM PSIRT advisory page CVE: CVE-1999-0009 NVD summary: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. References: ftp://patches.sgi.com/support/free/security/advi   sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   www.securityfocus.com/bid/134 Table of contents Symptom & Impact […]

Read more
IBM AIX 7.2 — CVE-1999-0064 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0064 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 31 January 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0064, IBM PSIRT advisory page CVE: CVE-1999-0064 NVD summary: Buffer overflow in AIX lquerylv program gives root access to local users. References: marc.info/?l=bugtraq&m=87602167418428&w=2   marc.info/?l=bugtraq&m=87602167418428&w=2 Table of contents Symptom & Impact Environment […]

Read more
CHAT