Linux

Ubuntu 14.04 — libcommons-collections3-java — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libcommons-collections3-java — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 May 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6936-1 Related CVEs: CVE-2015-4852 Upstream summary: It was discovered that Apache Commons Collections allowed serialization support for unsafe classes by default. A remote attacker could possibly use this issue to […]

Read more
SLES 12 — libXRes1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXRes1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 May 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1988 Upstream summary: Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
SLES 12 — guile — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — guile — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0394-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-8605 Upstream summary: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other […]

Read more
SLES 12 — sblim-sfcb — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — sblim-sfcb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2116-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5185 Upstream summary: The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference […]

Read more
Ubuntu 16.04 — sniffit — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — sniffit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 April 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4652-1 Related CVEs: CVE-2014-5439 Upstream summary: It was discovered that SniffIt incorrectly handled certain configuration files. An attacker could possibly use this issue to execute arbitrary code. Table of contents […]

Read more
SLES 12 — libsilc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsilc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:006 (see also SUSE bugzilla) Related CVEs: CVE-2008-1227 Upstream summary: Stack-based buffer overflow in the silc_fingerprint function in lib/silcutil/silcutil.c in Secure Internet Live Conferencing (SILC) Toolkit 1.1.5, and unspecified earlier versions, allows […]

Read more
SLES 12 — libpulse0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpulse0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0999-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3970 Upstream summary: The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of […]

Read more
Ubuntu 14.04 — cups-filters — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — cups-filters — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2838-1 Related CVEs: CVE-2015-8560 CVE-2015-8327 CVE-2015-3258 CVE-2015-3279 CVE-2015-2265 CVE-2014-2707 Upstream summary: Adam Chester discovered that the cups-filters foomatic-rip filter incorrectly stripped shell escape characters. A remote attacker could possibly use […]

Read more
Ubuntu 14.04 — nova — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nova — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 April 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3449-1 Related CVEs: CVE-2015-3241 CVE-2015-3280 CVE-2015-5162 CVE-2015-7548 CVE-2015-7713 CVE-2015-8749 CVE-2016-2140 CVE-2014-3608  +9 more Upstream summary: George Shuklin discovered that OpenStack Nova incorrectly handled the migration process. A remote authenticated user […]

Read more
SLES 12 — libpng15 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpng15 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2690 CVE-2011-2692 CVE-2011-2691 CVE-2011-3328 CVE-2011-3464 Upstream summary: Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when […]

Read more
CHAT