Operations

Ubuntu 14.04 — node-tar — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — node-tar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 May 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4777-1 Related CVEs: CVE-2015-8860 Upstream summary: It was discovered that node-tar mishandled certain tar archives. An attacker could use this vulnerability to write arbitrary files to the filesystem. Table of […]

Read more
SLES 12 — ibus-pinyin — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ibus-pinyin — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 May 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-4509 Upstream summary: The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does […]

Read more
Ubuntu 14.04 — tidy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — tidy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 April 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2695-1 Related CVEs: CVE-2015-5522 CVE-2015-5523 Upstream summary: Fernando Muñoz discovered that HTML Tidy incorrectly handled memory. If a user or automated system were tricked into processing specially crafted data, applications […]

Read more
Ubuntu 14.04 — webapps-greasemonkey — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — webapps-greasemonkey — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 April 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2743-3 Related CVEs: https://launchpad.net/bugs/1498681 https://launchpad.net/bugs/1069793 Upstream summary: USN-2743-1 fixed vulnerabilities in Firefox. Future Firefox updates will require all addons be signed and unity-firefox-extension, webapps-greasemonkey and webaccounts-browser-extension will not go through […]

Read more
SLES 12 — php5-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php5-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 27 April 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2012:0598-1 (see also SUSE bugzilla) Related CVEs: CVE-2012-1823 CVE-2012-2688 CVE-2010-2225 CVE-2010-2950 CVE-2012-0830 CVE-2013-6420 CVE-2006-7243 CVE-2010-3436  +12 more Upstream summary: sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a […]

Read more
SLES 12 — whois — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — whois — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 April 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2011:035 (see also SUSE bugzilla) Related CVEs: CVE-2011-2483 Upstream summary: crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle […]

Read more
Ubuntu 14.04 — nbd — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nbd — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 April 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2676-1 Related CVEs: CVE-2013-6410 CVE-2013-7441 CVE-2015-0847 Upstream summary: It was discovered that NBD incorrectly handled IP address matching. A remote attacker could use this issue with an IP address that […]

Read more
SLES 12 — perl-LWP-Protocol-https — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — perl-LWP-Protocol-https — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3230 Upstream summary: The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server […]

Read more
Ubuntu 14.04 — cinder — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — cinder — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 April 2015 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2405-1 Related CVEs: CVE-2014-3641 CVE-2014-7230 CVE-2013-1068 Upstream summary: Duncan Thomas discovered that OpenStack Cinder did not properly track the file format when using the GlusterFS of Smbfs drivers. A remote […]

Read more
SLES 12 — libgadu3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgadu3 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2015 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-3775 Upstream summary: libgadu before 1.11.4 and 1.12.0 before 1.12.0-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause […]

Read more
CHAT