Linux

SLES 12 — argyllcms — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — argyllcms — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1616 Upstream summary: Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-346 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-346 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 December 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2747-1 Related CVEs: CVE-2015-5950 Upstream summary: Dario Weisser discovered that the NVIDIA graphics drivers incorrectly handled certain IOCTL writes. A local attacker could use this issue to possibly gain root […]

Read more
SLES 12 — guestfsd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — guestfsd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 December 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1626-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4419 CVE-2013-2124 Upstream summary: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the –remote or –listen option, does not properly check the […]

Read more
SLES 12 — flash-player — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — flash-player — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 29 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1211-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-0578 CVE-2015-3114 CVE-2015-3115 CVE-2015-3116 CVE-2015-3117 CVE-2015-3118 CVE-2015-3119 CVE-2015-3120  +12 more Upstream summary: Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows […]

Read more
SLES 12 — perl-Net-Server — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-Net-Server — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0746-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-1841 Upstream summary: Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address, which might allow […]

Read more
SLES 12 — fastjar — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — fastjar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2635-1 (see also SUSE bugzilla) Related CVEs: CVE-2010-2322 Upstream summary: Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files […]

Read more
SLES 12 — ecryptfs-utils — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ecryptfs-utils — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2011:0898-1 (see also SUSE bugzilla) Related CVEs: CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 CVE-2011-1833 CVE-2014-9687 CVE-2015-8946  +3 more Upstream summary: utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows […]

Read more
SLES 12 — logrotate — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — logrotate — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2011:010 (see also SUSE bugzilla) Related CVEs: CVE-2011-1098 CVE-2011-1154 CVE-2011-1155 Upstream summary: Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data […]

Read more
SLES 12 — zoo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — zoo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2006:005 (see also SUSE bugzilla) Related CVEs: CVE-2006-0855 CVE-2007-1669 Upstream summary: Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Barracuda […]

Read more
Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 November 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4290-2 Related CVEs: CVE-2015-9542 Upstream summary: USN-4290-1 fixed a vulnerability in libpam-radius-auth. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It […]

Read more
CHAT