ubuntu

Ubuntu 14.04 — libvpx — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libvpx — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 July 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7249-1 Related CVEs: CVE-2024-5197 CVE-2023-5217 CVE-2020-0034 CVE-2017-13194 CVE-2019-9232 CVE-2019-9433 Upstream summary: Xiantong Hou discovered that libvpx would overflow when attempting to allocate memory for very large images. If an application […]

Read more
Ubuntu 20.04 — commons-io — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — commons-io — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 July 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8191-1 Related CVEs: CVE-2024-47554 CVE-2021-29425 Upstream summary: It was discovered that Apache Commons IO's XmlStreamReader class could excessively consume CPU resources under certain circumstances. An attacker could possibly use this […]

Read more
Ubuntu 18.04 — chromium-browser — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — chromium-browser — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 July 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6021-1 Related CVEs: CVE-2023-1528 CVE-2023-1530 CVE-2023-1531 CVE-2023-1533 CVE-2023-1811 CVE-2023-1815 CVE-2023-1818 CVE-2023-1529  +12 more Upstream summary: It was discovered that Chromium did not properly manage memory in several components. A remote […]

Read more
Ubuntu 18.04 — ruby-doorkeeper — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — ruby-doorkeeper — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6210-1 Related CVEs: CVE-2023-34246 Upstream summary: It was discovered that Doorkeeper incorrectly performed authorization checks for public clients that have been previous approved. An attacker could potentially exploit these in […]

Read more
Ubuntu 24.04 — cloud-init — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — cloud-init — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7677-1 Related CVEs: CVE-2024-6174 CVE-2024-11584 Upstream summary: Harry Sintonen discovered that the hotplugd socket in cloud-init was world writable. An attacker could possibly use this issue to send hotplug-hook commands. […]

Read more
Ubuntu 22.04 — xfpt — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — xfpt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 July 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7192-1 Related CVEs: CVE-2024-43700 Upstream summary: It was discovered that xfpt did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted file, […]

Read more
Ubuntu 22.04 — node-browserify-sign — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — node-browserify-sign — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6800-1 Related CVEs: CVE-2023-46234 Upstream summary: It was discovered that browserify-sign incorrectly handled an upper bound check in signature verification. If a user or an automated system were tricked into […]

Read more
Ubuntu 20.04 — gross — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — gross — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6942-1 Related CVEs: CVE-2023-52159 Upstream summary: It was discovered that Gross incorrectly handled memory when composing log entries. An attacker could possibly use this issue to cause Gross to crash, […]

Read more
Ubuntu 22.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7616-1 Related CVEs: CVE-2023-6378 CVE-2021-42550 Upstream summary: It was discovered that logback could read malicious configuration files from LDAP servers. An attacker with the required permissions could possibly use this […]

Read more
Ubuntu 14.04 — unbound — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — unbound — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 July 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7080-1 Related CVEs: CVE-2024-8508 CVE-2024-43167 CVE-2024-43168 CVE-2017-15105 CVE-2014-8602 Upstream summary: Toshifumi Sakaguchi discovered that Unbound incorrectly handled name compression for large RRsets, which could lead to excessive CPU usage. An […]

Read more
CHAT