Operations

SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam_krb5 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2008:027 (see also SUSE bugzilla) Related CVEs: CVE-2008-3825 CVE-2009-1384 Upstream summary: pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when […]

Read more
SLES 12 — openvas-manager — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — openvas-manager — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2014-9220 Upstream summary: SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the […]

Read more
Ubuntu 14.04 — nvidia-graphics-drivers-331 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — nvidia-graphics-drivers-331 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 November 2014 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2438-1 Related CVEs: CVE-2014-8091 CVE-2014-8098 CVE-2014-8298 Upstream summary: It was discovered that the NVIDIA graphics drivers incorrectly handled GLX indirect rendering support. An attacker able to connect to an X […]

Read more
SLES 12 — FastCGI — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — FastCGI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2011-2766 Upstream summary: The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request […]

Read more
SLES 12 — python-cinder — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-cinder — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:1467-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-3641 Upstream summary: The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from […]

Read more
SLES 12 — gnome-keyring — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gnome-keyring — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-3466 Upstream summary: GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a […]

Read more
Ubuntu 14.04 — lua5.1 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — lua5.1 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 November 2014 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-2338-1 Related CVEs: CVE-2014-5461 Upstream summary: It was discovered that Lua incorrectly handled certain vararg functions with a large number of fixed parameters. An attacker could use this issue to […]

Read more
SLES 12 — apache-commons-daemon — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache-commons-daemon — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 November 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory TID7009193 (see also SUSE bugzilla) Related CVEs: CVE-2011-2729 Upstream summary: native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 […]

Read more
SLES 12 — bogofilter — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bogofilter — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 October 2014 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:014 (see also SUSE bugzilla) Related CVEs: CVE-2010-2494 CVE-2012-5468 Upstream summary: Multiple buffer underflows in the base64 decoder in base64.c in (1) bogofilter and (2) bogolexer in bogofilter before 1.2.2 allow remote […]

Read more
CHAT