Linux

SLES 12 — cpp5 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — cpp5 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5276 Upstream summary: The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking […]

Read more
SLES 12 — libXrandr2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXrandr2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1986 Upstream summary: Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
SLES 12 — pcsc-ccid — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pcsc-ccid — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:003 (see also SUSE bugzilla) Related CVEs: CVE-2010-4530 Upstream summary: Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 […]

Read more
Ubuntu 14.04 — jakarta-taglibs-standard — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — jakarta-taglibs-standard — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2551-1 Related CVEs: CVE-2015-0254 Upstream summary: David Jorm discovered that the Apache Standard Taglibs incorrectly handled external XML entities. A remote attacker could possibly use this issue to execute arbitrary […]

Read more
SLES 12 — nrpe — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — nrpe — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0682-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-2913 Upstream summary: Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via […]

Read more
Ubuntu 14.04 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libevent — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 January 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3228-1 Related CVEs: CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 CVE-2014-6272 Upstream summary: Guido Vranken discovered that libevent incorrectly handled memory when processing certain data. A remote attacker could possibly use this issue with […]

Read more
SLES 12 — groff — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — groff — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2009-5044 CVE-2009-5080 CVE-2009-5081 Upstream summary: contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on […]

Read more
SLES 12 — audit — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — audit — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2020:858-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-5186 Upstream summary: Audit before 2.4.4 in Linux does not sanitize escape characters in filenames. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
SLES 12 — libvte9 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvte9 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2738 Upstream summary: The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) […]

Read more
SLES 12 — libXp6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXp6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1102-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2062 Upstream summary: Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow […]

Read more
CHAT