Linux

Ubuntu 16.04 — texlive-base — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — texlive-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3401-1 Related CVEs: CVE-2016-10243 Upstream summary: It was discovered that TeX Live incorrectly handled certain system commands. If a user were tricked into processing a specially crafted TeX file, a […]

Read more
SLES 12 — libXdmcp6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXdmcp6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 June 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1862-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-2625 Upstream summary: It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a […]

Read more
Ubuntu 14.04 — libiberty — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libiberty — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 June 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3368-1 Related CVEs: CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493  +1 more Upstream summary: It was discovered that libiberty incorrectly handled certain string operations. If a user or automated […]

Read more
Ubuntu 14.04 — awstats — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — awstats — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 June 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3518-1 Related CVEs: CVE-2017-1000501 Upstream summary: It was discovered that AWStats incorrectly filtered certain parameters. A remote attacker could possibly use this issue to execute arbitrary code. Table of contents […]

Read more
Ubuntu 16.04 — libxfont2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libxfont2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 June 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3500-1 Related CVEs: CVE-2017-16611 CVE-2017-13720 CVE-2017-13722 Upstream summary: It was discovered that libXfont incorrectly followed symlinks when opening font files. A local unprivileged user could use this issue to cause […]

Read more
Ubuntu 16.04 — collabtive — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — collabtive — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4590-1 Related CVEs: CVE-2015-0258 Upstream summary: It was discovered that Collabtive did not properly validate avatar image file uploads. An authenticated user could exploit this with a crafted file to […]

Read more
Ubuntu 14.04 — libytnef — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libytnef — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 June 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3667-1 Related CVEs: CVE-2017-12141 CVE-2017-9058 CVE-2017-9146 CVE-2017-9471 CVE-2017-9473 CVE-2017-6298 CVE-2017-6299 CVE-2017-6300  +9 more Upstream summary: It was discovered that libytnef incorrectly handled certain files. An attacker could possibly use this […]

Read more
SLES 12 — tcmu-runner — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tcmu-runner — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 June 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2601-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-1000198 CVE-2017-1000199 Upstream summary: tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service […]

Read more
SLES 12 — procmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — procmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 May 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1137-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3618 CVE-2017-16844 Upstream summary: Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and […]

Read more
Ubuntu 16.04 — iucode-tool — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — iucode-tool — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3186-1 Related CVEs: CVE-2017-0357 Upstream summary: It was discovered that iucode-tool incorrectly handled certain microcodes when using the -tr loader. If a user were tricked into processing a specially crafted […]

Read more
CHAT