Linux

Ubuntu 14.04 — qtbase-opensource-src — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — qtbase-opensource-src — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2626-1 Related CVEs: CVE-2014-0190 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Upstream summary: Wolfgang Schenk discovered that Qt incorrectly handled certain malformed GIF images. If a user or automated system were tricked into […]

Read more
SLES 12 — ruby2.1-rubygem-bundler — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ruby2.1-rubygem-bundler — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0795-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-0334 Upstream summary: Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with […]

Read more
SLES 12 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pcsc-lite — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:015 (see also SUSE bugzilla) Related CVEs: CVE-2010-0407 CVE-2010-4531 CVE-2016-10109 Upstream summary: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite […]

Read more
SLES 12 — libopenssl0_9_8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libopenssl0_9_8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:020 (see also SUSE bugzilla) Related CVEs: CVE-2009-3245 CVE-2009-4355 CVE-2009-5146 CVE-2010-4180 CVE-2010-4252 CVE-2011-4109 CVE-2011-4354 CVE-2011-5095  +4 more Upstream summary: OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand […]

Read more
SLES 12 — libspice-server1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libspice-server1 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0884-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4282 CVE-2015-3247 CVE-2015-5260 CVE-2015-5261 CVE-2016-0749 CVE-2016-2150 CVE-2016-9577 CVE-2016-9578  +3 more Upstream summary: Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows […]

Read more
SLES 12 — obs-service-source_validator — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — obs-service-source_validator — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1839-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-4007 Upstream summary: Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to […]

Read more
Ubuntu 14.04 — hplip — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — hplip — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 February 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2699-1 Related CVEs: CVE-2015-0839 Upstream summary: Enrico Zini discovered that HPLIP used a short GPG key ID when downloading keys from the keyserver. An attacker could possibly use this to […]

Read more
SLES 12 — lua — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lua — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 February 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-5461 Upstream summary: Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial […]

Read more
SLES 12 — powerpc-utils — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — powerpc-utils — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1211-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-4040 Upstream summary: snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing […]

Read more
Ubuntu 14.04 — nspr — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nspr — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 January 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3028-1 Related CVEs: CVE-2016-1951 CVE-2015-7183 CVE-2014-1545 Upstream summary: It was discovered that NSPR incorrectly handled memory allocation. A remote attacker could use this issue to cause NSPR to crash, resulting […]

Read more
CHAT