Linux

SLES 12 — libotr5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libotr5 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0706-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2851 Upstream summary: Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption […]

Read more
SLES 12 — libXfixes3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXfixes3 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1097-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1983 Upstream summary: Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — jakarta-taglibs-standard — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — jakarta-taglibs-standard — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1568-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-0254 Upstream summary: Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted […]

Read more
SLES 12 — perl-Tk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Tk — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2006:052 (see also SUSE bugzilla) Related CVEs: CVE-2006-4484 Upstream summary: Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-304-updates — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-304-updates — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 April 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2814-1 Related CVEs: CVE-2015-7869 CVE-2015-5950 CVE-2014-8091 CVE-2014-8098 CVE-2014-8298 Upstream summary: It was discovered that the NVIDIA graphics drivers incorrectly sanitized user mode inputs. A local attacker could use this issue […]

Read more
SLES 12 — bsh2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bsh2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0699-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-2510 Upstream summary: BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to […]

Read more
SLES 12 — xf86-video-intel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xf86-video-intel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2014-4910 Upstream summary: Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the interface […]

Read more
SLES 12 — python-pymongo — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-pymongo — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2132 Upstream summary: bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL […]

Read more
SLES 12 — doxygen — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — doxygen — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1570-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10245 Upstream summary: Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection. Table of contents Symptom & […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-346-updates — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-346-updates — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2747-1 Related CVEs: CVE-2015-5950 Upstream summary: Dario Weisser discovered that the NVIDIA graphics drivers incorrectly handled certain IOCTL writes. A local attacker could use this issue to possibly gain root […]

Read more
CHAT