Ubuntu 18.04

Ubuntu 18.04 — open-vm-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — open-vm-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 June 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7508-2 Related CVEs: CVE-2025-22247 CVE-2023-34058 CVE-2023-34059 CVE-2023-20900 CVE-2023-20867 CVE-2022-31676 Upstream summary: USN-7508-1 fixed a vulnerability in Open VM Tools. This update provides the corresponding update for Ubuntu 16.04 LTS and […]

Read more
Ubuntu 18.04 — vlc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — vlc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 June 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7243-1 Related CVEs: CVE-2024-46461 CVE-2023-47359 CVE-2023-47360 CVE-2019-19721 CVE-2020-13428 CVE-2021-25801 CVE-2021-25802 CVE-2021-25803  +12 more Upstream summary: It was discovered that VLC incorrectly handled memory when reading an MMS stream. An attacker […]

Read more
Ubuntu 18.04 — requests — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — requests — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7568-1 Related CVEs: CVE-2024-47081 CVE-2023-32681 CVE-2018-18074 Upstream summary: Dennis Brinkrolf and Tobias Funke discovered that Requests did not correctly handle certain HTTP headers. A remote attacker could possibly use this […]

Read more
Ubuntu 18.04 — matrix-synapse — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — matrix-synapse — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 May 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7444-1 Related CVEs: CVE-2023-32683 CVE-2023-43796 CVE-2022-39374 CVE-2023-41335 CVE-2022-39335 CVE-2023-42453 CVE-2024-31208 CVE-2024-53863  +7 more Upstream summary: It was discovered that Synapse network policies could be bypassed via specially crafted URLs. An […]

Read more
Ubuntu 18.04 — spip — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — spip — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 May 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7318-1 Related CVEs: CVE-2022-23638 CVE-2022-28959 CVE-2022-28960 CVE-2022-28961 CVE-2022-37155 CVE-2023-24258 CVE-2023-27372 CVE-2024-8517  +12 more Upstream summary: It was discovered that svg-sanitizer, vendored in SPIP, did not properly sanitize SVG/XML content. An […]

Read more
Ubuntu 18.04 — twitter-bootstrap3 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — twitter-bootstrap3 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7556-1 Related CVEs: CVE-2024-6484 CVE-2024-6531 CVE-2024-6485 Upstream summary: It was discovered that Bootstrap did not correctly sanitize certain input in the carousel component. An attacker could possibly use this issue […]

Read more
Ubuntu 18.04 — qtbase-opensource-src — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — qtbase-opensource-src — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 May 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8076-1 Related CVEs: CVE-2024-39936 CVE-2023-51714 CVE-2022-25255 CVE-2020-13962 CVE-2020-17507 CVE-2023-24607 CVE-2023-32762 CVE-2023-33285  +9 more Upstream summary: It was discovered that Qt did not correctly handle OpenSSL's error queue. An attacker could […]

Read more
Ubuntu 18.04 — openvpn — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — openvpn — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 May 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7340-1 Related CVEs: CVE-2017-12166 CVE-2024-5594 CVE-2022-0547 CVE-2020-11810 CVE-2020-15078 Upstream summary: It was discovered that OpenVPN did not perform proper input validation when generating a TLS key under certain configuration, which […]

Read more
Ubuntu 18.04 — google-guest-agent — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — google-guest-agent — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7956-1 Related CVEs: CVE-2025-58181 CVE-2024-45337 Upstream summary: Jakub Ciolek discovered that the Go Cryptography module included in Google Guest Agent did not validate GSSAPI authentication requests during SSH operations. An […]

Read more
Ubuntu 18.04 — netty — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — netty — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7918-1 Related CVEs: CVE-2025-58057 CVE-2025-58056 CVE-2025-59419 CVE-2022-24823 CVE-2024-29025 CVE-2020-11612 CVE-2021-21290 CVE-2021-21295  +12 more Upstream summary: Jeppe Bonde Weikop discovered that Netty incorrectly parsed HTTP messages. When Netty is used with […]

Read more
CHAT