Fix Prevention

IBM AIX 7.2 — CVE-2001-1095 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2001-1095 — buffer overflow — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 16 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2001-1095, IBM Support Bulletin CVE: CVE-2001-1095 NVD summary: Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter. References: archives.neohapsis.com/archives/aix/2001-q4/0000   www-1.ibm.com/support/search.wss?rs=0&q=IY24231& […]

Read more
Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libpam-radius-auth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 November 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4290-2 Related CVEs: CVE-2015-9542 Upstream summary: USN-4290-1 fixed a vulnerability in libpam-radius-auth. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It […]

Read more
SLES 12 — libXxf86vm1 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libXxf86vm1 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1103-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-2001 Upstream summary: Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary […]

Read more
IBM AIX 7.2 — CVE-1999-0048 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-1999-0048 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 14 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-1999-0048, IBM PSIRT advisory page CVE: CVE-1999-0048 NVD summary: Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. References: sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col   sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=col Table of contents […]

Read more
IBM AIX 7.2 — CVE-2009-1355 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2009-1355 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 11 November 2015 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2009-1355, IBM Support Bulletin CVE: CVE-2009-1355 NVD summary: Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename. References: aix.software.ibm.com/aix/efixes/security/muxatmd […]

Read more
Ubuntu 14.04 — webkitgtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — webkitgtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 November 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2937-1 Related CVEs: CVE-2014-1748 CVE-2015-1071 CVE-2015-1076 CVE-2015-1081 CVE-2015-1083 CVE-2015-1120 CVE-2015-1122 CVE-2015-1127  +12 more Upstream summary: A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. […]

Read more
SLES 12 — gzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 November 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:008 (see also SUSE bugzilla) Related CVEs: CVE-2010-0001 CVE-2009-2624 Upstream summary: Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably […]

Read more
CHAT