Linux

SLES 15 — log4j12 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — log4j12 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-5645 Upstream summary: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from […]

Read more
Ubuntu 14.04 — memcached — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — memcached — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 January 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3601-1 Related CVEs: CVE-2018-1000127 CVE-2017-9951 CVE-2018-1000115 CVE-2016-8704 CVE-2016-8705 CVE-2016-8706 Upstream summary: It was discovered that Memcached incorrectly handled reusing certain items. A remote attacker could possibly use this issue to […]

Read more
Ubuntu 18.04 — prosody — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — prosody — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4834-1 Related CVEs: CVE-2018-10847 Upstream summary: It was discovered that Prosody incorrectly validated the virtual host associated with a user session across stream restarts. A remote attacker could use this […]

Read more
SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fuse — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:005 (see also SUSE bugzilla) Related CVEs: CVE-2011-0541 CVE-2015-3202 CVE-2018-10906 CVE-2009-3297 Upstream summary: fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount […]

Read more
Ubuntu 16.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4778-1 Related CVEs: CVE-2015-8869 CVE-2018-9838 Upstream summary: It was discovered that OCaml mishandled sign extensions. A remote attacker could use this vulnerability to steal sensitive information, cause a denial of […]

Read more
SLES 15 — argyllcms — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — argyllcms — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1616 Upstream summary: Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause […]

Read more
Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-10860 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2010-2529 Upstream summary: Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of […]

Read more
Ubuntu 14.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 December 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4229-1 Related CVEs: CVE-2018-12327 CVE-2018-7182 CVE-2018-7183 CVE-2018-7184 CVE-2018-7185 CVE-2016-2519 CVE-2016-7426 CVE-2016-7427  +12 more Upstream summary: It was discovered that ntpq and ntpdc incorrectly handled some arguments. An attacker could possibly […]

Read more
Ubuntu 14.04 — libraw — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libraw — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 December 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3838-1 Related CVEs: CVE-2018-5807 CVE-2018-5810 CVE-2018-5811 CVE-2018-5812 CVE-2018-5813 CVE-2018-5815 CVE-2018-5816 CVE-2017-16909  +12 more Upstream summary: It was discovered that LibRaw incorrectly handled photo files. If a user or automated system […]

Read more
CHAT