Linux

Ubuntu 16.04 — nspr — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nspr — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 October 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3028-1 Related CVEs: CVE-2016-1951 Upstream summary: It was discovered that NSPR incorrectly handled memory allocation. A remote attacker could use this issue to cause NSPR to crash, resulting in a […]

Read more
SLES 12 — libass5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libass5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 October 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:3107-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-7970 CVE-2016-7971 CVE-2016-7969 CVE-2016-7972 Upstream summary: Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial […]

Read more
Ubuntu 16.04 — libimobiledevice — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libimobiledevice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 October 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3026-1 Related CVEs: CVE-2016-5104 Upstream summary: It was discovered that libimobiledevice incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to […]

Read more
Ubuntu 16.04 — network-manager-applet — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — network-manager-applet — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3217-1 Related CVEs: https://launchpad.net/bugs/1668321 Upstream summary: Frederic Bardy and Quentin Biguenet discovered that network-manager-applet incorrectly checked permissions when connecting to certain wireless networks. A local attacker could use this issue […]

Read more
Ubuntu 14.04 — ecryptfs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — ecryptfs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2876-1 Related CVEs: CVE-2016-1572 CVE-2014-9687 Upstream summary: Jann Horn discovered that mount.ecryptfs_private would mount over certain directories in the proc filesystem. A local attacker could use this to escalate their […]

Read more
Ubuntu 16.04 — hibagent — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — hibagent — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6493-2 Related CVEs: https://launchpad.net/bugs/2043739 Upstream summary: USN-6493-1 fixed a vulnerability in hibagent. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: On […]

Read more
SLES 12 — perl-XML-Twig — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-XML-Twig — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 September 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2172-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9180 Upstream summary: perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless […]

Read more
Ubuntu 14.04 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 September 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3063-1 Related CVEs: CVE-2016-5384 Upstream summary: Tobias Stoeckmann discovered that Fontconfig incorrectly handled cache files. A local attacker could possibly use this issue with a specially crafted cache file to […]

Read more
Ubuntu 16.04 — vnc4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — vnc4 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 September 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4772-1 Related CVEs: CVE-2015-0255 CVE-2015-1283 Upstream summary: USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides the corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2015-0255) USN-2726-1 […]

Read more
SLES 12 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 September 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2186-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5384 Upstream summary: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks […]

Read more
CHAT