IT, Cloud & DevOps Blog

Ubuntu 14.04 — php-gettext — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — php-gettext — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4779-1 Related CVEs: CVE-2015-8980 Upstream summary: Danilo Segan discovered that Gettext mishandled certain input. An attacker could use this vulnerability to execute arbitrary code. Table of contents Symptom & Impact […]

Read more
SLES 12 — libimobiledevice6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libimobiledevice6 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2142 Upstream summary: userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack […]

Read more
SLES 12 — libgssglue1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgssglue1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2709 Upstream summary: libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary […]

Read more
Ubuntu 14.04 — libwmf — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libwmf — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2670-1 Related CVEs: CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696 Upstream summary: Fernando Muñoz and Stefan Cornelius discovered that libwmf incorrectly handled certain malformed images. If a user or automated system were tricked […]

Read more
SLES 12 — python-neutron — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-neutron — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0018-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-6414 CVE-2014-7821 CVE-2014-3555 CVE-2014-8153 Upstream summary: OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default […]

Read more
Ubuntu 14.04 — serf — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — serf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2315-1 Related CVEs: CVE-2014-3504 Upstream summary: Ben Reser discovered that serf did not correctly handle SSL certificates with NUL bytes in the CommonName or SubjectAltNames fields. A remote attacker could […]

Read more
SLES 12 — mozilla-nspr — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — mozilla-nspr — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1680-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-4500 CVE-2015-4501 CVE-2015-4506 CVE-2015-4509 CVE-2015-4511 CVE-2015-4517 CVE-2015-4519 CVE-2015-4520  +8 more Upstream summary: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and […]

Read more
SLES 12 — obs-service-set_version — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — obs-service-set_version — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 January 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-0593 Upstream summary: The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1 […]

Read more
SLES 12 — tftp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tftp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 January 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2199 Upstream summary: Buffer overflow in tftp-hpa before 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the […]

Read more
CHAT