Linux

SLES 12 — lighttpd — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — lighttpd — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 September 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0474-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-2323 CVE-2014-2324 CVE-2013-4508 CVE-2010-0295 CVE-2011-4362 CVE-2012-5533 CVE-2013-4559 CVE-2013-4560  +2 more Upstream summary: SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to […]

Read more
Ubuntu 14.04 — xorg-server-lts-utopic — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — xorg-server-lts-utopic — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2500-1 Related CVEs: CVE-2013-6424 CVE-2015-0255 Upstream summary: Olivier Fourdan discovered that the X.Org X server incorrectly handled XkbSetGeometry requests resulting in an information leak. An attacker able to connect to […]

Read more
SLES 12 — python-pywbem — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-pywbem — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0580-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-6418 Upstream summary: PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an […]

Read more
Ubuntu 14.04 — libyaml-libyaml-perl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libyaml-libyaml-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2461-2 Related CVEs: CVE-2014-9130 Upstream summary: Stanisław Pitucha and Jonathan Gray discovered that libyaml-libyaml-perl did not properly handle wrapped strings. An attacker could create specially crafted YAML data to trigger […]

Read more
Ubuntu 14.04 — node-semver — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — node-semver — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4776-1 Related CVEs: CVE-2015-8855 Upstream summary: It was discovered that semver incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial of service. Table […]

Read more
SLES 12 — perl-PlRPC — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-PlRPC — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:2238-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-7284 Upstream summary: The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execute arbitrary code via […]

Read more
SLES 12 — libtool — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libtool — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:006 (see also SUSE bugzilla) Related CVEs: CVE-2009-3736 Upstream summary: ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other […]

Read more
Ubuntu 14.04 — fuse — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — fuse — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2617-1 Related CVEs: CVE-2015-3202 Upstream summary: Tavis Ormandy discovered that FUSE incorrectly filtered environment variables. A local attacker could use this issue to gain administrative privileges. Table of contents Symptom […]

Read more
SLES 12 — hardlink — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hardlink — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2011-3630 CVE-2011-3631 CVE-2011-3632 Upstream summary: Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote […]

Read more
Ubuntu 14.04 — bsd-mailx — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — bsd-mailx — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2455-1 Related CVEs: CVE-2014-7844 Upstream summary: It was discovered that bsd-mailx contained a feature that allowed syntactically valid email addresses to be treated as shell commands. A remote attacker could […]

Read more
CHAT