Linux

Ubuntu 14.04 — jasper — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — jasper — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3693-1 Related CVEs: CVE-2015-5203 CVE-2015-5221 CVE-2016-10248 CVE-2016-10250 CVE-2016-8883 CVE-2016-8887 CVE-2016-9262 CVE-2016-9387  +12 more Upstream summary: It was discovered that JasPer incorrectly handled certain malformed JPEG-2000 image files. If a user […]

Read more
SLES 12 — hexchat — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hexchat — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2872-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2087 Upstream summary: Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. […]

Read more
Ubuntu 14.04 — gtk-vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — gtk-vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 March 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3203-1 Related CVEs: CVE-2017-5884 CVE-2017-5885 Upstream summary: It was discovered that gtk-vnc incorrectly validated certain data. A malicious server could use this issue to cause gtk-vnc to crash, resulting in […]

Read more
SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — SuSEfirewall2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2923-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-15638 Upstream summary: The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 […]

Read more
Ubuntu 16.04 — valgrind — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — valgrind — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3337-1 Related CVEs: CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493  +1 more Upstream summary: It was discovered that Valgrind incorrectly handled certain string operations. If a user or automated […]

Read more
Ubuntu 16.04 — nvidia-graphics-drivers-304 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nvidia-graphics-drivers-304 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3240-1 Related CVEs: CVE-2017-0318 CVE-2016-8826 CVE-2016-7382 CVE-2016-7389 Upstream summary: It was discovered that the NVIDIA graphics drivers contained a flaw in the kernel mode layer. A local attacker could use […]

Read more
Ubuntu 16.04 — wildmidi — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — wildmidi — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4807-1 Related CVEs: CVE-2017-11661 CVE-2017-11662 CVE-2017-11663 CVE-2017-11664 Upstream summary: It was discovered that WildMIDI incorrectly handled certain MID files. A remote attacker could possibly use this issue to cause a […]

Read more
Ubuntu 16.04 — libxi — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libxi — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5646-1 Related CVEs: CVE-2016-7945 CVE-2016-7946 Upstream summary: Tobias Stoeckmann discovered that libXi did not properly manage memory when handling X server responses. A remote attacker could use this issue to […]

Read more
Ubuntu 14.04 — libnl3 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libnl3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3311-1 Related CVEs: CVE-2017-0553 Upstream summary: It was discovered that libnl incorrectly handled memory when performing certain operations. A local attacker could possibly use this issue to cause libnl to […]

Read more
Ubuntu 14.04 — imlib2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — imlib2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3075-1 Related CVEs: CVE-2011-5326 CVE-2014-9762 CVE-2014-9763 CVE-2014-9764 CVE-2014-9771 CVE-2016-3993 CVE-2016-3994 CVE-2016-4024 Upstream summary: Jakub Wilk discovered an out of bounds read in the GIF loader implementation in Imlib2. An attacker […]

Read more
CHAT