Linux

Ubuntu 16.04 — ubufox — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ubufox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 August 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3391-2 Related CVEs: https://launchpad.net/bugs/1711137 Upstream summary: USN-3391-1 fixed vulnerabilities in Firefox. This update provides the corresponding update for Ubufox. Original advisory details: Multiple security issues were discovered in Firefox. If […]

Read more
Ubuntu 14.04 — horizon — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — horizon — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 August 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3447-1 Related CVEs: CVE-2016-4428 CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 CVE-2014-3594 Upstream summary: Beth Lancaster and Brandon Sawyers discovered that OpenStack Horizon was incorrect protected against cross-site scripting (XSS) attacks. A remote authenticated […]

Read more
Ubuntu 14.04 — pcsc-lite — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — pcsc-lite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3176-1 Related CVEs: CVE-2016-10109 Upstream summary: Peter Wu discovered that the PC/SC service did not correctly handle certain resources. A local attacker could use this issue to cause PC/SC to […]

Read more
Ubuntu 16.04 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3063-1 Related CVEs: CVE-2016-5384 Upstream summary: Tobias Stoeckmann discovered that Fontconfig incorrectly handled cache files. A local attacker could possibly use this issue with a specially crafted cache file to […]

Read more
Ubuntu 16.04 — bsdiff — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — bsdiff — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4500-1 Related CVEs: CVE-2014-9862 Upstream summary: It was discovered that bsdiff mishandled certain input. If a user were tricked into opening a malicious file, an attacker could cause bsdiff to […]

Read more
SLES 12 — ruby2.1-rubygem-archive-tar-minitar — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-archive-tar-minitar — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 July 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:0115-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10173 Upstream summary: Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files […]

Read more
Ubuntu 14.04 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 July 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2817-1 Related CVEs: CVE-2015-5234 CVE-2015-5235 Upstream summary: It was discovered that IcedTea Web incorrectly handled applet URLs. A remote attacker could possibly use this issue to inject applets into the […]

Read more
Ubuntu 16.04 — mcabber — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — mcabber — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 July 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4506-1 Related CVEs: CVE-2016-9928 Upstream summary: It was discovered that MCabber does not properly manage roster pushes. An attacker could possibly use this issue to remotely perform machine-in-the-middle attacks. (CVE-2016-9928). […]

Read more
Ubuntu 14.04 — libvdpau — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libvdpau — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 July 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2729-1 Related CVEs: CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 Upstream summary: Florian Weimer discovered that libvdpau incorrectly handled certain environment variables. A local attacker could possibly use this issue to gain privileges. Table […]

Read more
SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 June 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:723-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8079 CVE-2016-6354 Upstream summary: qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
CHAT