Linux

SLES 12 — ipsec-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ipsec-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 July 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1367-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-4047 CVE-2016-10396 Upstream summary: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via […]

Read more
Ubuntu 16.04 — sleuthkit — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — sleuthkit — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4765-1 Related CVEs: CVE-2012-5619 CVE-2017-13755 Upstream summary: It was discovered that The Sleuth Kit did not properly handle certain entires in FAT file systems. An attacker could use this vulnerability […]

Read more
Ubuntu 16.04 — libidn — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libidn — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3434-1 Related CVEs: CVE-2017-14062 CVE-2015-2059 CVE-2015-8948 CVE-2016-6261 CVE-2016-6262 CVE-2016-6263 Upstream summary: It was discovered that Libidn incorrectly handled decoding certain digits. A remote attacker could use this issue to cause […]

Read more
Ubuntu 16.04 — php-gettext — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — php-gettext — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4779-1 Related CVEs: CVE-2015-8980 Upstream summary: Danilo Segan discovered that Gettext mishandled certain input. An attacker could use this vulnerability to execute arbitrary code. Table of contents Symptom & Impact […]

Read more
Debian 9 — xml-security-c — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — xml-security-c — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 July 2017 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
Ubuntu 16.04 — sssd — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — sssd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3526-1 Related CVEs: CVE-2017-12173 Upstream summary: It was discovered that SSSD incorrectly handled certain inputs when querying its local cache. An attacker could use this to inject arbitrary code and […]

Read more
Ubuntu 14.04 — bsh — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — bsh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2923-1 Related CVEs: CVE-2016-2510 Upstream summary: Alvaro Muñoz and Christian Schneider discovered that BeanShell incorrectly handled deserialization. A remote attacker could possibly use this issue to execute arbitrary code. Table […]

Read more
Debian 9 — gnutls28 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — gnutls28 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 July 2017 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-7507 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — shotwell — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — shotwell — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 June 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3379-1 Related CVEs: CVE-2017-1000024 Upstream summary: It was discovered that Shotwell is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext […]

Read more
Ubuntu 16.04 — opensaml2 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — opensaml2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 June 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7364-1 Related CVEs: https://launchpad.net/bugs/2103420 Upstream summary: Alexander Tan discovered that the OpenSAML C++ library was susceptible to forging of signed SAML messages. An attacker could possibly use this issue to […]

Read more
CHAT