Linux

SLES 12 — php7-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php7-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3622 CVE-2015-0235 CVE-2014-3538 CVE-2015-1352 CVE-2015-3416 CVE-2014-9426 Upstream summary: Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow […]

Read more
SLES 12 — libXinerama1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXinerama1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 January 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1985 Upstream summary: Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — python-pycrypto — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-pycrypto — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0869-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2417 CVE-2013-1445 Upstream summary: PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the […]

Read more
SLES 12 — libxcb1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libxcb1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1096-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2064 Upstream summary: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via […]

Read more
SLES 12 — kernel-azure — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kernel-azure — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1527-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4343 Upstream summary: Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and […]

Read more
Ubuntu 14.04 — click — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — click — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2771-1 Related CVEs: https://launchpad.net/bugs/1506467 CVE-2015-8768 Upstream summary: It was discovered that click did not properly perform input sanitization during click package installation. If a user were tricked into installing a […]

Read more
SLES 12 — libsmi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsmi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:001 (see also SUSE bugzilla) Related CVEs: CVE-2010-2891 Upstream summary: Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier […]

Read more
SLES 12 — id3lib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — id3lib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2007:019 (see also SUSE bugzilla) Related CVEs: CVE-2007-4460 Upstream summary: The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on […]

Read more
SLES 12 — python-python-memcached — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-python-memcached — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-3221 CVE-2015-3241 CVE-2015-3280 CVE-2015-5240 CVE-2015-7713 Upstream summary: OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote […]

Read more
SLES 12 — dstat — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dstat — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2009-3894 Upstream summary: Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working […]

Read more
CHAT