Ubuntu 20.04

Ubuntu 20.04 — freeglut — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — freeglut — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 April 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7870-1 Related CVEs: CVE-2024-24258 CVE-2024-24259 Upstream summary: It was discovered that Freeglut incorrectly managed memory, resulting in a memory leak. An attacker could possibly use this issue to cause a […]

Read more
Ubuntu 20.04 — thunderbird — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — thunderbird — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 April 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7193-1 Related CVEs: CVE-2024-11694 CVE-2024-9680 CVE-2024-7519 CVE-2024-7521 CVE-2024-7522 CVE-2024-7525 CVE-2024-7526 CVE-2024-7527  +12 more Upstream summary: Masato Kinugawa discovered that Thunderbird did not properly validate the CSP policy in the Web […]

Read more
Ubuntu 20.04 — freeradius — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — freeradius — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7055-1 Related CVEs: CVE-2024-3596 CVE-2019-17185 CVE-2022-41860 CVE-2022-41861 Upstream summary: Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl discovered that FreeRADIUS incorrectly authenticated certain responses. […]

Read more
Ubuntu 20.04 — c-ares — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — c-ares — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6676-1 Related CVEs: CVE-2024-25629 CVE-2020-22217 CVE-2023-31130 CVE-2023-32067 CVE-2022-4904 CVE-2021-3672 Upstream summary: Vojtěch Vobr discovered that c-ares incorrectly handled user input from local configuration files. An attacker could possibly use this […]

Read more
Ubuntu 20.04 — python-werkzeug — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — python-werkzeug — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6799-1 Related CVEs: CVE-2024-34069 CVE-2023-23934 CVE-2023-25577 Upstream summary: It was discovered that the debugger in Werkzeug was not restricted to trusted hosts. A remote attacker could possibly use this issue […]

Read more
Ubuntu 20.04 — haproxy — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — haproxy — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6530-1 Related CVEs: CVE-2023-45539 CVE-2023-40225 CVE-2023-25725 CVE-2023-0056 CVE-2022-0711 CVE-2021-40346 https://launchpad.net/bugs/1940314 Upstream summary: It was discovered that HAProxy incorrectly handled URI components containing the hash character (#). A remote attacker could […]

Read more
Ubuntu 20.04 — civicrm — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — civicrm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8242-1 Related CVEs: CVE-2023-28447 Upstream summary: Takuya Aramaki discovered that Smarty, vendored in CiviCRM, did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a […]

Read more
Ubuntu 20.04 — giflib — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — giflib — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6824-1 Related CVEs: CVE-2021-40633 CVE-2022-28506 CVE-2023-39742 Upstream summary: It was discovered that GIFLIB incorrectly handled certain GIF files. An attacker could possibly use this issue to cause a denial of […]

Read more
Ubuntu 20.04 — libclamunrar — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libclamunrar — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6569-1 Related CVEs: CVE-2022-30333 CVE-2023-40477 Upstream summary: it was discovered that libclamunrar incorrectly handled directories when extracting RAR archives. A remote attacker could possibly use this issue to overwrite arbitrary […]

Read more
Ubuntu 20.04 — pillow — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — pillow — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6744-1 Related CVEs: CVE-2024-28219 CVE-2023-44271 CVE-2023-50447 CVE-2022-24303 CVE-2022-45198 CVE-2022-22817 CVE-2021-23437 CVE-2021-34552  +12 more Upstream summary: Hugo van Kemenade discovered that Pillow was not properly performing bounds checks when processing an […]

Read more
CHAT