Linux

SLES 12 — librpcsecgss3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — librpcsecgss3 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2007:019 (see also SUSE bugzilla) Related CVEs: CVE-2007-3999 Upstream summary: Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through […]

Read more
Ubuntu 14.04 — mime-support — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — mime-support — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 July 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2453-1 Related CVEs: CVE-2014-7209 Upstream summary: Timothy D. Morgan discovered that the run-mailcap tool incorrectly filtered certain shell metacharacters in filenames. If a user or automated system were tricked into […]

Read more
SLES 12 — libsrtp1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsrtp1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-2139 Upstream summary: Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-352 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-352 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2814-1 Related CVEs: CVE-2015-7869 Upstream summary: It was discovered that the NVIDIA graphics drivers incorrectly sanitized user mode inputs. A local attacker could use this issue to possibly gain root […]

Read more
SLES 12 — xrdb — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xrdb — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2011:016 (see also SUSE bugzilla) Related CVEs: CVE-2011-0465 Upstream summary: xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a […]

Read more
Ubuntu 14.04 — libmodule-signature-perl — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libmodule-signature-perl — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 July 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2607-1 Related CVEs: CVE-2015-3406 CVE-2015-3407 CVE-2015-3408 CVE-2015-3409 Upstream summary: John Lightsey discovered that Module::Signature incorrectly handled PGP signature boundaries. A remote attacker could use this issue to trick Module::Signature into […]

Read more
SLES 12 — radvd — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — radvd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-3602 Upstream summary: Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote […]

Read more
Ubuntu 14.04 — ubufox — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — ubufox — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 July 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3391-2 Related CVEs: https://launchpad.net/bugs/1711137 https://launchpad.net/bugs/1498681 https://launchpad.net/bugs/1483858 https://launchpad.net/bugs/1398174 Upstream summary: USN-3391-1 fixed vulnerabilities in Firefox. This update provides the corresponding update for Ubufox. Original advisory details: Multiple security issues were discovered […]

Read more
SLES 12 — perl-XML-Parser — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-XML-Parser — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:7679 (see also SUSE bugzilla) Related CVEs: CVE-2006-10002 CVE-2006-10003 Upstream summary: XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and […]

Read more
SLES 12 — libneon27 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libneon27 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 July 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2009:018 (see also SUSE bugzilla) Related CVEs: CVE-2009-2473 CVE-2009-2474 Upstream summary: neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause […]

Read more
CHAT