Linux

SLES 15 — liboath0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liboath0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2013-7322 Upstream summary: usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which […]

Read more
Debian 9 — discount — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — discount — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-11468 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 9 — git-annex — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — git-annex — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-12976 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 14.04 — screen-resolution-extra — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — screen-resolution-extra — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3607-1 Related CVEs: CVE-2018-8885 Upstream summary: It was discovered that Screen Resolution Extra was using PolicyKit in an unsafe manner. A local attacker could potentially exploit this issue to bypass […]

Read more
Amazon Linux 2 — corosync — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — corosync — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2018-1014 Related CVEs: CVE-2018-1084 Upstream summary: Integer overflow in exec/totemcrypto.c:authenticate_nss_2_3() function An integer overflow leading to an out-of-bound read was found in authenticate_nss_2_3() in Corosync. An attacker could craft a […]

Read more
SLES 15 — libcacard0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcacard0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1058-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-6414 Upstream summary: Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of […]

Read more
Ubuntu 18.04 — libcgroup — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libcgroup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4845-1 Related CVEs: CVE-2018-14348 Upstream summary: It was discovered that libcgroup incorrectly handled log file permissions. An attacker could possibly use this issue to obtain sensitive information. Table of contents […]

Read more
SLES 15 — postgresql — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — postgresql — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3107-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14798 Upstream summary: A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their […]

Read more
Debian 9 — keystone — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — keystone — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-14432 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — lighttpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — lighttpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4775-1 Related CVEs: CVE-2015-3200 CVE-2018-19052 Upstream summary: It was discovered that Lighttpd did not properly sanitized the string used in basic HTTP authentication method. A remote attacker could use this […]

Read more
CHAT