Linux

SLES 12 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1283-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-6272 CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 Upstream summary: Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta […]

Read more
Ubuntu 16.04 — harfbuzz — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — harfbuzz — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 January 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5746-1 Related CVEs: CVE-2015-9274 CVE-2015-8947 CVE-2016-2052 Upstream summary: Behzad Najjarpour Jabbari discovered that HarfBuzz incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial […]

Read more
Ubuntu 14.04 — eog — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — eog — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3069-1 Related CVEs: CVE-2016-6855 CVE-2013-7447 Upstream summary: It was discovered that Eye of GNOME incorrectly handled certain invalid UTF-8 strings. If a user were tricked into opening a specially-crafted image, […]

Read more
SLES 12 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 January 2017 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1926-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4566 CVE-2015-5244 CVE-2016-3099 Upstream summary: mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting […]

Read more
Ubuntu 16.04 — ubuntu-release-upgrader — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ubuntu-release-upgrader — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3623-1 Related CVEs: https://launchpad.net/bugs/1174007 Upstream summary: It was discovered that ubuntu-release-upgrader did not correctly drop permissions before opening a browser to view the release notes. This update fixes the issue. […]

Read more
Ubuntu 16.04 — libxfixes — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libxfixes — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5437-1 Related CVEs: CVE-2016-7944 Upstream summary: Tobias Stoeckmann discovered that libXfixes incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service, or possibly […]

Read more
SLES 12 — bash — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bash — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 December 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1212-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2016-9401 CVE-2012-6711 CVE-2014-7186 CVE-2014-7187  +4 more Upstream summary: GNU Bash through 4.3 processes trailing strings after function definitions in the values […]

Read more
SLES 12 — kdump — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kdump — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 December 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2553-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5759 Upstream summary: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as […]

Read more
Ubuntu 16.04 — node-minimatch — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — node-minimatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 December 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4783-1 Related CVEs: CVE-2016-10540 Upstream summary: It was discovered that minimatch did not perform necessary bounds checking on regular expressions. An attacker could use this vulnerability to cause a denial […]

Read more
Ubuntu 14.04 — evolution-data-server — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — evolution-data-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 December 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3724-1 Related CVEs: CVE-2016-10727 Upstream summary: Jon Kristensen discovered that Evolution Data Server would automatically downgrade a connection to an IMAP server if the IMAP server did not support SSL. […]

Read more
CHAT