Linux

Ubuntu 14.04 — commons-httpclient — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — commons-httpclient — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2769-1 Related CVEs: CVE-2012-5783 CVE-2012-6153 CVE-2014-3577 CVE-2015-5262 Upstream summary: It was discovered that Apache Commons HttpClient did not properly verify the Common Name or subjectAltName fields of X.509 certificates. An […]

Read more
SLES 12 — perl-HTML-Parser — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-HTML-Parser — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2009:020 (see also SUSE bugzilla) Related CVEs: CVE-2009-3627 Upstream summary: The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an […]

Read more
SLES 12 — libmms0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmms0 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-2892 Upstream summary: Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execute arbitrary code via a […]

Read more
SLES 12 — ctdb-devel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ctdb-devel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0845-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4159 Upstream summary: ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp […]

Read more
SLES 12 — libgwengui-qt4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgwengui-qt4 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0072-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7542 Upstream summary: A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. Table of contents Symptom & Impact […]

Read more
Ubuntu 14.04 — glib-networking — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — glib-networking — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 August 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2913-2 Related CVEs: https://launchpad.net/bugs/1528645 Upstream summary: USN-2913-1 removed 1024-bit RSA CA certificates from the ca-certificates package. This update adds support for alternate certificate chains to the glib-networking package to properly […]

Read more
SLES 12 — hyper-v — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — hyper-v — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 August 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2012:1673-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-2669 CVE-2012-5532 Upstream summary: The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of […]

Read more
SLES 12 — python-keystoneclient — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-keystoneclient — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-0105 Upstream summary: The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from […]

Read more
SLES 12 — libunwind — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libunwind — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0284-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-3239 Upstream summary: Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes. […]

Read more
CHAT