Linux

Ubuntu 14.04 — mono — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — mono — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2547-1 Related CVEs: CVE-2011-0992 CVE-2012-3543 CVE-2015-2318 CVE-2015-2319 CVE-2015-2320 Upstream summary: It was discovered that the Mono TLS implementation was vulnerable to the SKIP-TLS vulnerability. A remote attacker could possibly use […]

Read more
SLES 12 — pam-modules — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam-modules — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 March 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1760-1 (see also SUSE bugzilla) Related CVEs: CVE-2011-3172 Upstream summary: A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are […]

Read more
Ubuntu 14.04 — node-minimatch — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — node-minimatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 March 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4783-1 Related CVEs: CVE-2016-10540 Upstream summary: It was discovered that minimatch did not perform necessary bounds checking on regular expressions. An attacker could use this vulnerability to cause a denial […]

Read more
SLES 12 — empathy — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — empathy — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-3635 Upstream summary: Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows […]

Read more
SLES 12 — portus — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — portus — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:0435-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7576 CVE-2015-7577 CVE-2015-7578 CVE-2015-7579 CVE-2015-7580 CVE-2015-7581 CVE-2016-0752 CVE-2016-0753  +3 more Upstream summary: The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller […]

Read more
SLES 12 — libXrender1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXrender1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1095-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1987 Upstream summary: Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
Ubuntu 14.04 — dpkg — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — dpkg — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2820-1 Related CVEs: CVE-2015-0860 CVE-2015-0840 CVE-2014-3864 CVE-2014-3865 CVE-2014-0471 Upstream summary: Hanno Boeck discovered that the dpkg-deb tool incorrectly handled certain old style Debian binary packages. If a user or an […]

Read more
SLES 12 — libmikmod3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmikmod3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 21 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1471-1 (see also SUSE bugzilla) Related CVEs: CVE-2010-2546 CVE-2009-0179 CVE-2009-3995 CVE-2009-3996 CVE-2007-6720 Upstream summary: Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote attackers to execute arbitrary code […]

Read more
SLES 12 — yast2-users — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — yast2-users — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1138-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-1601 Upstream summary: yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an […]

Read more
SLES 12 — libmodplug1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmodplug1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2011:0943-1 (see also SUSE bugzilla) Related CVEs: CVE-2011-1761 CVE-2013-4233 CVE-2013-4234 Upstream summary: Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote […]

Read more
CHAT