Operations

SLES 15 — mozilla-nspr — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — mozilla-nspr — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 June 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:1926-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7183 CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 CVE-2020-15683 CVE-2020-15969 CVE-2021-23981  +4 more Upstream summary: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla […]

Read more
Oracle Linux 8 — fribidi — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — fribidi — vulnerability — patch and remediation guide (ELSA-2022-7514)

🟡 Medium   ⏱ 10–30 min  Last verified: 25 June 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-7514 Related CVEs: CVE-2022-25309 CVE-2022-25310 CVE-2022-25308 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification […]

Read more
IBM AIX 7.3 — CVE-1999-0129 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-1999-0129 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 24 June 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-1999-0129, IBM PSIRT advisory page CVE: CVE-1999-0129 NVD summary: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. References: www.cert.org/advisories/CA-1996-25.html   www.cert.org/advisories/CA-1996-25.html […]

Read more
IBM AIX 7.3 — CVE-2003-0285 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2003-0285 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 24 June 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2003-0285, IBM PSIRT advisory page CVE: CVE-2003-0285 NVD summary: IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, […]

Read more
FreeBSD 13 — py39-flask-caching — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-flask-caching — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-flask-caching — remote code execution or local privilege escalation vulnerabilities Related CVEs: CVE-2021-33026 Upstream summary: subnix reports: The Flask-Caching extension through 2.0.2 for Flask relies on Pickle for serialization, which […]

Read more
FreeBSD 12 — ircii — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ircii — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ircII — denial of service Related CVEs: CVE-2021-29376 Upstream summary: Michael Ortmann reports: ircii has a bug in parsing CTCP UTC messages. Its unknown if this could also be used […]

Read more
FreeBSD 13 — libvncserver — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libvncserver — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libvncserver — multiple buffer overflows Related CVEs: CVE-2014-6051 CVE-2014-6052 CVE-2014-6053 CVE-2014-6054 CVE-2014-6055 CVE-2016-9941 CVE-2016-9942 Upstream summary: libvnc server reports: Two unrelated buffer overflows can be used by a malicious server […]

Read more
FreeBSD 13 — botan — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — botan — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: botan2 — Side channel during ECC key generation Related CVEs: CVE-2014-9742 CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-2849 CVE-2018-12435  +1 more Upstream summary: botan2 developers reports: A timing side channel during […]

Read more
FreeBSD 13 — vips — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — vips — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Fix a buffer overflow in the tiff reader Upstream summary: libvips reports: A buffer overflow was found and fixed in the libvips code Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 13 — python+ipv — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — python+ipv — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: python — buffer overrun in repr() for unicode strings Related CVEs: CVE-2005-0089 CVE-2006-4980 Upstream summary: Benjamin C. Wiley Sittler reports: I discovered a [buffer overrun in repr() for unicode strings]. […]

Read more
CHAT