IT, Cloud & DevOps Blog

SLES 12 — php7-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php7-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3622 CVE-2015-0235 CVE-2014-3538 CVE-2015-1352 CVE-2015-3416 CVE-2014-9426 Upstream summary: Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow […]

Read more
SLES 12 — libXinerama1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXinerama1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1985 Upstream summary: Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — python-pycrypto — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-pycrypto — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0869-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2417 CVE-2013-1445 Upstream summary: PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the […]

Read more
IBM AIX 7.2 — CVE-2003-0694 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2003-0694 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 30 December 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2003-0694, IBM PSIRT advisory page CVE: CVE-2003-0694 NVD summary: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function […]

Read more
IBM AIX 7.2 — CVE-2003-0285 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2003-0285 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 29 December 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2003-0285, IBM PSIRT advisory page CVE: CVE-2003-0285 NVD summary: IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, […]

Read more
CHAT