Linux

Ubuntu 16.04 — node-semver — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — node-semver — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4776-1 Related CVEs: CVE-2015-8855 Upstream summary: It was discovered that semver incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial of service. Table […]

Read more
SLES 12 — yubikey-manager — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yubikey-manager — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2017-15631 Upstream summary: TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file. Table […]

Read more
SLES 12 — libopus0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopus0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0436-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-0381 Upstream summary: An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its […]

Read more
Debian 9 — enigmail — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — enigmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 July 2017 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-17843 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 12 — libzip2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libzip2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:009 (see also SUSE bugzilla) Related CVEs: CVE-2011-0421 CVE-2012-1162 CVE-2012-1163 CVE-2015-2331 CVE-2017-14107 Upstream summary: The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a […]

Read more
SLES 12 — libquicktime0 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libquicktime0 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0610-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2399 CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125 CVE-2017-9126 CVE-2017-9127 CVE-2017-9128 Upstream summary: Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to […]

Read more
SLES 12 — lhasa — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lhasa — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1091-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2347 Upstream summary: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted […]

Read more
Ubuntu 16.04 — nvidia-graphics-drivers-375 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nvidia-graphics-drivers-375 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3305-1 Related CVEs: CVE-2017-0350 CVE-2017-0351 CVE-2017-0352 CVE-2016-8826 CVE-2017-0318 Upstream summary: It was discovered that the NVIDIA graphics drivers contained flaws in the kernel mode layer. A local attacker could use […]

Read more
Ubuntu 16.04 — npm — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — npm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4785-1 Related CVEs: CVE-2016-3956 Upstream summary: It was discovered that the npm command-line interface mishandled certain sensitive information. An attacker could use this vulnerability to collect authentication information that could […]

Read more
Debian 9 — cups — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — cups — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 July 2017 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15400 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT