Linux

Ubuntu 14.04 — python-keystoneclient — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — python-keystoneclient — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 June 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2705-1 Related CVEs: CVE-2014-7144 CVE-2015-1852 Upstream summary: Qin Zhao discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, […]

Read more
Ubuntu 14.04 — linux-lts-utopic — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — linux-lts-utopic — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 May 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3036-1 Related CVEs: CVE-2016-3070 CVE-2016-4482 CVE-2016-4565 CVE-2016-4569 CVE-2016-4578 CVE-2016-4580 CVE-2016-4913 CVE-2016-4997  +12 more Upstream summary: Jan Stancek discovered that the Linux kernel's memory manager did not properly handle moving pages […]

Read more
Ubuntu 14.04 — t1utils — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — t1utils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 May 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2627-1 Related CVEs: CVE-2015-3905 Upstream summary: Jakub Wilk discovered that t1utils incorrectly handled certain malformed fonts. If a user or automated system were tricked into opening a specially crafted font, […]

Read more
Ubuntu 16.04 — eog — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — eog — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3069-1 Related CVEs: CVE-2016-6855 Upstream summary: It was discovered that Eye of GNOME incorrectly handled certain invalid UTF-8 strings. If a user were tricked into opening a specially-crafted image, a […]

Read more
SLES 12 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgme0 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:3250-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 Upstream summary: Stack-based buffer overflow in game-music-emu before 0.6.1. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 12 — libstorage5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libstorage5 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2189-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5746 Upstream summary: libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users […]

Read more
Ubuntu 14.04 — nettle — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nettle — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3193-1 Related CVEs: CVE-2016-6489 CVE-2015-8803 CVE-2015-8804 CVE-2015-8805 Upstream summary: It was discovered that Nettle incorrectly mitigated certain timing side-channel attacks. A remote attacker could possibly use this flaw to recover […]

Read more
SLES 12 — pidgin-otr — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pidgin-otr — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0703-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2369 CVE-2015-8833 Upstream summary: Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might […]

Read more
Ubuntu 16.04 — r-base — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — r-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 May 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4799-1 Related CVEs: CVE-2016-8714 Upstream summary: It was discovered that a buffer overflow in R causes memory corruption. An attacker could possibly use this to cause a denial of service […]

Read more
Ubuntu 16.04 — ec2-hibinit-agent — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ec2-hibinit-agent — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 May 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6519-2 Related CVEs: https://launchpad.net/bugs/1941785 Upstream summary: USN-6519-1 added IMDSv2 support to EC2 hibagent. This update provides the corresponding update for Ubuntu 16.04 LTS. Original advisory details: The EC2 hibagent package […]

Read more
CHAT