Troubleshooting

SLES 12 — kdump — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kdump — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 December 2016 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:2553-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-5759 Upstream summary: The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as […]

Read more
IBM AIX 7.2 — CVE-2006-6914 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2006-6914 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 11 December 2016 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2006-6914, IBM Support Bulletin CVE: CVE-2006-6914 NVD summary: Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors. References: ftp://aix.software.ibm.com/aix/efixes/security/R […]

Read more
Ubuntu 16.04 — node-minimatch — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — node-minimatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 December 2016 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4783-1 Related CVEs: CVE-2016-10540 Upstream summary: It was discovered that minimatch did not perform necessary bounds checking on regular expressions. An attacker could use this vulnerability to cause a denial […]

Read more
Ubuntu 14.04 — evolution-data-server — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — evolution-data-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 December 2016 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3724-1 Related CVEs: CVE-2016-10727 Upstream summary: Jon Kristensen discovered that Evolution Data Server would automatically downgrade a connection to an IMAP server if the IMAP server did not support SSL. […]

Read more
CHAT