Linux

Ubuntu 16.04 — libupnp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libupnp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 September 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4794-1 Related CVEs: CVE-2016-6255 CVE-2016-8863 Upstream summary: Matthew Garrett discovered that libupnp mishandled POST requests by default. An attacker could use this vulnerability to write files to arbitrary locations in […]

Read more
Ubuntu 14.04 — linux-lts-vivid — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — linux-lts-vivid — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 September 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3053-1 Related CVEs: CVE-2016-1237 CVE-2016-4470 CVE-2016-4794 CVE-2016-5243 CVE-2016-3070 CVE-2016-4482 CVE-2016-4569 CVE-2016-4578  +12 more Upstream summary: A missing permission check when settings ACLs was discovered in nfsd. A local user could […]

Read more
Ubuntu 16.04 — libtorrent-rasterbar — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libtorrent-rasterbar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4790-1 Related CVEs: CVE-2016-5301 Upstream summary: It was discovered that libtorrent incorrectly handled chunked headers. A remote attacker could possibly use this to cause a crash resulting in a denial […]

Read more
Ubuntu 14.04 — file-roller — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — file-roller — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 August 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3074-1 Related CVEs: CVE-2016-7162 https://launchpad.net/bugs/1171236 Upstream summary: It was discovered that File Roller incorrectly handled symlinks. If a user were tricked into extracting a specially-crafted archive, an attacker could delete […]

Read more
Ubuntu 14.04 — texlive-base — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — texlive-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 August 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3401-1 Related CVEs: CVE-2016-10243 Upstream summary: It was discovered that TeX Live incorrectly handled certain system commands. If a user were tricked into processing a specially crafted TeX file, a […]

Read more
Ubuntu 16.04 — dosfstools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — dosfstools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 August 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2986-1 Related CVEs: CVE-2015-8872 CVE-2016-4804 Upstream summary: Hanno Böck discovered that dosfstools incorrectly handled certain malformed filesystems. A local attacker could use this issue to cause dosfstools to crash, resulting […]

Read more
Ubuntu 14.04 — libtorrent-rasterbar — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libtorrent-rasterbar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 August 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4790-1 Related CVEs: CVE-2016-5301 Upstream summary: It was discovered that libtorrent incorrectly handled chunked headers. A remote attacker could possibly use this to cause a crash resulting in a denial […]

Read more
Ubuntu 14.04 — libimobiledevice — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libimobiledevice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 August 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3026-1 Related CVEs: CVE-2016-5104 Upstream summary: It was discovered that libimobiledevice incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to […]

Read more
Ubuntu 16.04 — libspring-java — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libspring-java — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 August 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4774-1 Related CVEs: CVE-2015-3192 CVE-2015-5211 CVE-2016-9878 CVE-2014-0225 CVE-2014-3625 CVE-2014-3578 Upstream summary: Toshiaki Maki discovered that Spring Framework incorrectly handled certain XML files. A remote attacker could exploit this with a […]

Read more
CHAT