Common Problems

Debian 9 — libpam4j — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — libpam4j — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 April 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-12197 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 14.04 — exempi — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — exempi — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 April 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3668-1 Related CVEs: CVE-2017-18233 CVE-2017-18234 CVE-2017-18236 CVE-2017-18238 CVE-2018-7728 CVE-2018-7729 CVE-2018-7730 CVE-2018-7731 Upstream summary: It was discovered that Exempi incorrectly handled certain media files. If a user or automated system were […]

Read more
SLES 12 — taglib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — taglib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 April 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1374-2 (see also SUSE bugzilla) Related CVEs: CVE-2018-11439 CVE-2012-2396 Upstream summary: The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted […]

Read more
Ubuntu 14.04 — sleuthkit — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — sleuthkit — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4765-1 Related CVEs: CVE-2012-5619 CVE-2017-13755 Upstream summary: It was discovered that The Sleuth Kit did not properly handle certain entires in FAT file systems. An attacker could use this vulnerability […]

Read more
SLES 12 — libgit2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgit2 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 April 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0433-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2016-8568 CVE-2016-8569 CVE-2017-5338 CVE-2017-5339 CVE-2018-10887  +4 more Upstream summary: Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol […]

Read more
Ubuntu 16.04 — collectd — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — collectd — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 April 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4793-1 Related CVEs: CVE-2016-6254 CVE-2017-16820 CVE-2017-7401 Upstream summary: It was discovered that collectd mishandled certain malformed packets. A remote attacker could use this vulnerability to cause collectd to crash or […]

Read more
Debian 9 — python3.5 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — python3.5 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 April 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-1000158 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — libmwaw — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libmwaw — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 April 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3319-1 Related CVEs: CVE-2017-9433 Upstream summary: It was discovered that libmwaw incorrectly handled certain malformed document files. If a user or automated system were tricked into opening a specially crafted […]

Read more
Ubuntu 14.04 — mongodb — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — mongodb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8064-1 Related CVEs: CVE-2018-20802 Upstream summary: Eliot Horowitz discovered that MongoDB may fail to validate some instances of malformed BSON. A remote attacker could possibly use this issue to cause […]

Read more
SLES 12 — rubygem-passenger — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rubygem-passenger — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 March 2018 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:2337-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7519 CVE-2017-1000384 CVE-2017-16355 CVE-2018-12029 Upstream summary: agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone […]

Read more
CHAT