ubuntu

Ubuntu 18.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 June 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7616-1 Related CVEs: CVE-2023-6378 CVE-2021-42550 Upstream summary: It was discovered that logback could read malicious configuration files from LDAP servers. An attacker with the required permissions could possibly use this […]

Read more
Ubuntu 14.04 — wpa — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — wpa — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 June 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6945-1 Related CVEs: CVE-2024-5290 https://launchpad.net/bugs/2067613 CVE-2021-27803 CVE-2020-12695 CVE-2021-0326 CVE-2019-16275 CVE-2019-11555 CVE-2016-10743  +12 more Upstream summary: Rory McNamara discovered that wpa_supplicant could be made to load arbitrary shared objects by unprivileged […]

Read more
Ubuntu 22.04 — vips — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — vips — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 June 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6437-1 Related CVEs: CVE-2018-7998 CVE-2019-6976 CVE-2020-20739 CVE-2021-27847 CVE-2023-40032 Upstream summary: Ziqiang Gu discovered that VIPS could be made to dereference a NULL pointer. If a user or automated system were […]

Read more
Ubuntu 18.04 — opensc — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — opensc — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 June 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7346-2 Related CVEs: https://launchpad.net/bugs/2104948 CVE-2021-42780 CVE-2021-42782 CVE-2023-2977 CVE-2023-40660 CVE-2023-40661 CVE-2023-5992 CVE-2024-45615  +11 more Upstream summary: USN-7346-1 fixed vulnerabilities in OpenSC. The update introduced a regression in Ubuntu 16.04 LTS, Ubuntu […]

Read more
Ubuntu 22.04 — procps — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — procps — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 June 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6477-1 Related CVEs: CVE-2023-4016 Upstream summary: It was discovered that the procps-ng ps tool incorrectly handled memory. An attacker could possibly use this issue to cause procps-ng to crash, resulting […]

Read more
Ubuntu 24.04 — pymongo — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — pymongo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6904-1 Related CVEs: CVE-2024-5629 Upstream summary: It was discovered that PyMongo incorrectly handled certain BSON. An attacker could possibly use this issue to read sensitive information or cause a crash. […]

Read more
Ubuntu 22.04 — kmail-account-wizard — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — kmail-account-wizard — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7732-1 Related CVEs: CVE-2024-50624 Upstream summary: It was discovered that KMail Account Wizard used HTTP rather than HTTPS when retrieving certain email server configurations. An attacker could possibly use this […]

Read more
Ubuntu 20.04 — golang-1.18 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — golang-1.18 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 June 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7109-1 Related CVEs: CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24531 CVE-2023-24536 CVE-2023-29402 CVE-2023-29403 CVE-2023-29404  +12 more Upstream summary: Philippe Antoine discovered that Go incorrectly handled crafted HTTP/2 streams. An attacker could possibly use […]

Read more
Ubuntu 22.04 — djoser — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — djoser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 June 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7354-1 Related CVEs: CVE-2024-21543 Upstream summary: Diego Cebrián discovered that djoser did not properly handle user authentication. An attacker with valid credentials could possibly use this to bypass authentication checks, […]

Read more
Ubuntu 14.04 — yajl — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — yajl — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 June 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6233-1 Related CVEs: CVE-2017-16516 CVE-2022-24795 CVE-2023-33460 Upstream summary: It was discovered that YAJL was not properly performing bounds checks when decoding a string with escape sequences. If a user or […]

Read more
CHAT