IT, Cloud & DevOps Blog

SLES 12 — powerpc-utils — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — powerpc-utils — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1211-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-4040 Upstream summary: snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing […]

Read more
Ubuntu 14.04 — nspr — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nspr — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 January 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3028-1 Related CVEs: CVE-2016-1951 CVE-2015-7183 CVE-2014-1545 Upstream summary: It was discovered that NSPR incorrectly handled memory allocation. A remote attacker could use this issue to cause NSPR to crash, resulting […]

Read more
SLES 12 — cpp5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cpp5 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5276 Upstream summary: The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking […]

Read more
IBM AIX 7.2 — CVE-1999-0524 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0524 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 28 January 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0524, IBM PSIRT advisory page CVE: CVE-1999-0524 NVD summary: ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. References: descriptions.securescout.com/tc/11010   descriptions.securescout.com/tc/11011   kb.juniper.net/InfoCenter/index?page=content&id= Table of contents […]

Read more
SLES 12 — libXrandr2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXrandr2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1986 Upstream summary: Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
IBM AIX 7.2 — CVE-1999-0851 — denial of service — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0851 — denial of service — patch and remediation guide

🟢 Low   ⏱ 10–30 min  Last verified: 26 January 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0851, IBM PSIRT advisory page CVE: CVE-1999-0851 NVD summary: Denial of service in BIND named via naptr. References: ftp://ftp.caldera.com/pub/security/OpenLinux/CSS   sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   www.securityfocus.com/bid/788 Table of contents Symptom & Impact Environment & Reproduction […]

Read more
SLES 12 — pcsc-ccid — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pcsc-ccid — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:003 (see also SUSE bugzilla) Related CVEs: CVE-2010-4530 Upstream summary: Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 […]

Read more
CHAT