Linux

SLES 12 — rtkit — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rtkit — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4326 Upstream summary: RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended […]

Read more
SLES 12 — libgnomesu — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgnomesu — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-1946 Upstream summary: gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid […]

Read more
SLES 12 — cracklib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cracklib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-6318 Upstream summary: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) […]

Read more
SLES 12 — telepathy-idle — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — telepathy-idle — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1364-1 (see also SUSE bugzilla) Related CVEs: CVE-2007-6746 Upstream summary: telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain […]

Read more
SLES 12 — libvdpau1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvdpau1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1892-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 Upstream summary: libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, […]

Read more
SLES 12 — coolkey — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — coolkey — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2007-4129 Upstream summary: CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory. Table of […]

Read more
SLES 12 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 15 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2058-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7705 CVE-2015-7853 CVE-2015-7871 CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 CVE-2014-9297  +12 more Upstream summary: The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 […]

Read more
Ubuntu 14.04 — rabbitmq-server — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — rabbitmq-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3374-1 Related CVEs: CVE-2016-9877 Upstream summary: It was discovered that RabbitMQ incorrectly handled MQTT (MQ Telemetry Transport) authentication. A remote attacker could use this issue to authenticate successfully with an […]

Read more
SLES 12 — libXv1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXv1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1104-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1989 CVE-2013-2066 Upstream summary: Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer […]

Read more
SLES 12 — xfsprogs — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xfsprogs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2383-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2150 Upstream summary: xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a […]

Read more
CHAT