Ubuntu 20.04

Ubuntu 20.04 — amd64-microcode — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — amd64-microcode — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7077-1 Related CVEs: CVE-2023-31315 CVE-2023-20569 CVE-2023-20593 Upstream summary: Enrique Nissim and Krzysztof Okupski discovered that some AMD processors did not properly restrict access to the System Management Mode (SMM) configuration […]

Read more
Ubuntu 20.04 — node-eventsource — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — node-eventsource — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6082-1 Related CVEs: CVE-2022-1650 Upstream summary: It was discovered that EventSource incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input […]

Read more
Ubuntu 20.04 — audiofile — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — audiofile — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6558-1 Related CVEs: CVE-2018-13440 CVE-2018-17095 CVE-2019-13147 CVE-2022-24599 Upstream summary: It was discovered that audiofile could be made to dereference invalid memory. If a user or an automated system were tricked […]

Read more
Ubuntu 20.04 — shadow — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — shadow — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6640-1 Related CVEs: CVE-2023-4641 https://launchpad.net/bugs/1998169 CVE-2013-4235 Upstream summary: It was discovered that shadow was not properly sanitizing memory when running the password utility. An attacker could possibly use this issue […]

Read more
Ubuntu 20.04 — virglrenderer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — virglrenderer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5309-1 Related CVEs: CVE-2022-0135 CVE-2022-0175 Upstream summary: It was discovered that virglrenderer incorrectly handled memory. An attacker inside a guest could use this issue to cause virglrenderer to crash, resulting […]

Read more
Ubuntu 20.04 — tang — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — tang — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6489-1 Related CVEs: CVE-2023-1672 Upstream summary: Brian McDermott discovered that Tang incorrectly handled permissions when creating/rotating keys. A local attacker could possibly use this issue to read the keys. Table […]

Read more
Ubuntu 20.04 — gsasl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — gsasl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6169-1 Related CVEs: CVE-2022-2469 Upstream summary: It was discovered that GNU SASL's GSSAPI server could make an out-of-bounds reads if given specially crafted GSS-API authentication data. A remote attacker could […]

Read more
Ubuntu 20.04 — slurm-llnl — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — slurm-llnl — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6458-1 Related CVEs: CVE-2022-29500 CVE-2022-29501 CVE-2022-29502 CVE-2016-10030 CVE-2017-15566 CVE-2018-7033 CVE-2018-10995 CVE-2019-6438  +4 more Upstream summary: It was discovered that Slurm did not properly handle credential management, which could allow an […]

Read more
Ubuntu 20.04 — libhtml-stripscripts-perl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libhtml-stripscripts-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6100-1 Related CVEs: CVE-2023-24038 Upstream summary: It was discovered that HTML::StripScripts does not properly parse HTML content with certain style attributes. A remote attacker could use this issue to cause […]

Read more
Ubuntu 20.04 — libcaca — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libcaca — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 January 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7943-1 Related CVEs: CVE-2022-0856 CVE-2021-30498 CVE-2021-30499 CVE-2021-3410 Upstream summary: Han Zheng discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause libcaca to crash. […]

Read more
CHAT