ubuntu

Ubuntu 22.04 — orc — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — orc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 November 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6964-1 Related CVEs: CVE-2024-40897 Upstream summary: Noriko Totsuka discovered that ORC incorrectly handled certain crafted file. An attacker could possibly use this issue to execute arbitrary code. Table of contents […]

Read more
Ubuntu 16.04 — libsndfile — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libsndfile — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 November 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7267-1 Related CVEs: CVE-2024-50612 CVE-2022-33065 CVE-2021-4156 CVE-2021-3246 CVE-2017-12562 CVE-2017-14245 CVE-2017-14246 CVE-2017-14634  +12 more Upstream summary: It was discovered that libsndfile incorrectly handled certain malformed OggVorbis files. An attacker could possibly […]

Read more
Ubuntu 16.04 — yard — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — yard — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 November 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6731-1 Related CVEs: CVE-2017-17042 CVE-2019-1020001 CVE-2024-27285 Upstream summary: It was discovered that YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct […]

Read more
Ubuntu 18.04 — rails — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — rails — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 November 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7646-1 Related CVEs: CVE-2019-5418 CVE-2024-41128 CVE-2024-47887 CVE-2024-47888 CVE-2024-47889 Upstream summary: It was discovered that Rails did not correctly handle headers. An attacker could potentially use this issue to view arbitrary […]

Read more
Ubuntu 20.04 — requests — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — requests — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 November 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7568-1 Related CVEs: CVE-2024-47081 CVE-2023-32681 Upstream summary: Dennis Brinkrolf and Tobias Funke discovered that Requests did not correctly handle certain HTTP headers. A remote attacker could possibly use this issue […]

Read more
Ubuntu 24.04 — gstreamer1.0 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — gstreamer1.0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 November 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7174-1 Related CVEs: CVE-2024-47606 Upstream summary: Antonio Morales discovered that GStreamer incorrectly handled allocating memory for certain buffers. An attacker could use this issue to cause GStreamer to crash, resulting […]

Read more
Ubuntu 20.04 — orc — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — orc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 November 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6964-1 Related CVEs: CVE-2024-40897 Upstream summary: Noriko Totsuka discovered that ORC incorrectly handled certain crafted file. An attacker could possibly use this issue to execute arbitrary code. Table of contents […]

Read more
Common Problems 116419

Ubuntu 24.04 LTS Cloud-Init Overwrites Netplan on Reboot

🟡 Medium   ⏱ 5–30 min  Last verified: 1 November 2024 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & Cross-Refs References & Further […]

Read more
Ubuntu 22.04 — libmodule-scandeps-perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — libmodule-scandeps-perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 October 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7117-1 Related CVEs: CVE-2024-10224 CVE-2024-11003 CVE-2024-48990 CVE-2024-48991 CVE-2024-48992 Upstream summary: Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly […]

Read more
Ubuntu 16.04 — openjpeg2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — openjpeg2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 October 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7223-1 Related CVEs: CVE-2024-56826 CVE-2024-56827 CVE-2021-29338 CVE-2021-3575 CVE-2022-1122 CVE-2023-39327 CVE-2020-6851 CVE-2020-8112  +12 more Upstream summary: Frank Zeng discovered that OpenJPEG incorrectly handled memory when using the decompression utility. An attacker […]

Read more
CHAT