Ubuntu 18.04

Ubuntu 18.04 — maven-shared-utils — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — maven-shared-utils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 May 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6730-1 Related CVEs: CVE-2022-29599 Upstream summary: It was discovered that Apache Maven Shared Utils did not handle double-quoted strings properly, allowing shell injection attacks. This could allow an attacker to […]

Read more
Common Problems 118003

Ubuntu 18.04 LTS unattended-upgrades hangs and blocks dpkg lock

🟡 Medium   ⏱ 5–30 min  Last verified: 3 May 2023 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & Cross-Refs References & Further […]

Read more
Ubuntu 18.04 — cargo — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — cargo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 May 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6275-1 Related CVEs: CVE-2023-38497 Upstream summary: Addison Crump discovered that Cargo incorrectly set file permissions on UNIX-like systems when extracting crate archives. If the crate would contain files writable by […]

Read more
Ubuntu 18.04 — apr-util — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — apr-util — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5870-1 Related CVEs: CVE-2022-25147 Upstream summary: Ronald Crane discovered that APR-util did not properly handled memory when encoding or decoding certain input data. An attacker could possibly use this issue […]

Read more
Ubuntu 18.04 — edk2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — edk2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7060-1 Related CVEs: CVE-2019-0161 CVE-2021-28210 CVE-2021-28211 CVE-2021-38575 CVE-2021-38578 CVE-2022-1292 CVE-2017-5731 CVE-2018-12182  +12 more Upstream summary: It was discovered that EDK II did not check the buffer length in XHCI, which […]

Read more
Ubuntu 18.04 — u-boot — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — u-boot — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5764-1 Related CVEs: CVE-2022-2347 CVE-2022-30552 CVE-2022-30767 CVE-2022-30790 CVE-2022-33103 CVE-2022-33967 CVE-2022-34835 Upstream summary: It was discovered that U-Boot incorrectly handled certain USB DFU download setup packets. A local attacker could use […]

Read more
Ubuntu 18.04 — htmlunit — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — htmlunit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8220-1 Related CVEs: CVE-2023-49093 Upstream summary: It was discovered that HtmlUnit was vulnerable to remote code execution via XSLT when browsing an attacker-controlled webpage. An attacker could possibly use this […]

Read more
Ubuntu 18.04 — apache-log4j1.2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — apache-log4j1.2 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5998-1 Related CVEs: CVE-2022-23302 CVE-2022-23305 CVE-2022-23307 CVE-2019-17571 CVE-2021-4104 Upstream summary: It was discovered that the SocketServer component of Apache Log4j 1.2 incorrectly handled deserialization. An attacker could possibly use this […]

Read more
Ubuntu 18.04 — linux-raspi2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — linux-raspi2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6191-1 Related CVEs: https://launchpad.net/bugs/2020279 CVE-2023-0459 CVE-2023-1118 CVE-2023-1513 CVE-2023-2162 CVE-2023-32269 CVE-2023-1829 CVE-2022-3903  +12 more Upstream summary: USN-6081-1, USN-6084-1, USN-6092-1 and USN-6095-1 fixed vulnerabilities in the Linux kernel. Unfortunately, that update introduced […]

Read more
CHAT