Linux

Ubuntu 16.04 — optipng — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — optipng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3495-1 Related CVEs: CVE-2017-1000229 Upstream summary: It was discovered that OptiPNG incorrectly handled memory. A remote attacker could use this issue with a specially crafted image file to cause OptiPNG […]

Read more
Ubuntu 14.04 — qpdf — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — qpdf — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3638-1 Related CVEs: CVE-2015-9252 CVE-2017-11624 CVE-2017-11625 CVE-2017-11626 CVE-2017-11627 CVE-2017-12595 CVE-2017-18183 CVE-2017-18184  +6 more Upstream summary: It was discovered that QPDF incorrectly handled certain malformed files. A remote attacker could use […]

Read more
Ubuntu 16.04 — doxygen — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — doxygen — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 February 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4002-1 Related CVEs: CVE-2016-10245 Upstream summary: It was discovered that Doxygen incorrectly handled certain queries. An attacker could possibly use this issue to execute arbitrary code and compromise sensitive information. […]

Read more
SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2673 CVE-2016-9427 Upstream summary: Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in […]

Read more
SLES 12 — libidn11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libidn11 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14062 CVE-2015-8948 CVE-2016-6261 CVE-2016-6262 CVE-2016-6263 Upstream summary: Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a […]

Read more
Ubuntu 14.04 — pacemaker — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — pacemaker — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 February 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3462-1 Related CVEs: CVE-2016-7035 CVE-2016-7797 Upstream summary: Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled the IPC interface. A local attacker could possibly use this issue to execute […]

Read more
Ubuntu 14.04 — wayland — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — wayland — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 February 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3622-1 Related CVEs: CVE-2017-16612 Upstream summary: It was discovered that the Wayland Xcursor support incorrectly handled certain files. An attacker could use these issues to cause Wayland to crash, resulting […]

Read more
SLES 12 — libXfont2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXfont2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 February 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-16611 Upstream summary: In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, […]

Read more
Ubuntu 16.04 — dns-root-data — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — dns-root-data — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3715-1 Related CVEs: https://launchpad.net/bugs/1721129 Upstream summary: This update adds the latest DNSSEC validation trust anchor required for the upcoming Root Zone KSK Rollover and refreshes the list of root hints. […]

Read more
SLES 12 — postgresql94 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — postgresql94 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0077-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-12172 Upstream summary: PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under […]

Read more
CHAT