ubuntu

Ubuntu 20.04 — request-tracker4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — request-tracker4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 May 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6529-1 Related CVEs: CVE-2021-38562 CVE-2022-25802 CVE-2023-41259 CVE-2023-41260 Upstream summary: It was discovered that Request Tracker incorrectly handled certain inputs. If a user or an automated system were tricked into opening […]

Read more
Ubuntu 16.04 — tinyproxy — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — tinyproxy — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 May 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7190-1 Related CVEs: CVE-2023-49606 CVE-2022-40468 CVE-2017-11747 Upstream summary: It was discovered that Tinyproxy did not properly manage memory during the parsing of HTTP connection headers. An attacker could use this […]

Read more
Ubuntu 16.04 — fdkaac — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — fdkaac — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 May 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7660-1 Related CVEs: CVE-2023-34823 CVE-2022-37781 CVE-2022-36148 CVE-2023-34824 Upstream summary: It was discovered that fdkaac did not correctly handle certain input. If a user or automated system were tricked into opening […]

Read more
Ubuntu 22.04 — opensc — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — opensc — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 May 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7346-1 Related CVEs: CVE-2021-42780 CVE-2021-42782 CVE-2023-2977 CVE-2023-40660 CVE-2023-40661 CVE-2023-5992 CVE-2024-45615 CVE-2024-45616  +5 more Upstream summary: It was discovered that OpenSC did not correctly handle certain memory operations, which could lead […]

Read more
Ubuntu 22.04 — activemq — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — activemq — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7268-1 Related CVEs: CVE-2022-41678 CVE-2023-46604 CVE-2015-7559 CVE-2018-11775 CVE-2020-13920 CVE-2021-26117 Upstream summary: It was discovered that Apache ActiveMQ incorrectly handled authentication. A remote attacker could possibly use this issue to run […]

Read more
Ubuntu 22.04 — ruby-carrierwave — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — ruby-carrierwave — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7497-1 Related CVEs: CVE-2021-21305 CVE-2023-49090 Upstream summary: Rikita Ishikawa discovered that CarrierWave did not correctly sanitize certain inputs. An attacker could possibly use this issue to execute arbitrary code. This […]

Read more
Ubuntu 20.04 — node-path-to-regexp — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — node-path-to-regexp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8290-1 Related CVEs: CVE-2024-45296 Upstream summary: It was discovered that Path-to-Regexp incorrectly handled route patterns containing multiple named parameters separated by non-delimiter characters such as hyphens. An attacker could possibly […]

Read more
Ubuntu 24.04 — python-flask-cors — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — python-flask-cors — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7612-1 Related CVEs: CVE-2024-6839 CVE-2024-6866 CVE-2024-6844 CVE-2024-6221 CVE-2024-1681 Upstream summary: It was discovered that Flask-CORS did not correctly handle certain regular expressions. A remote attacker could possibly use this issue […]

Read more
Ubuntu 22.04 — vte2.91 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — vte2.91 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6833-1 Related CVEs: CVE-2024-37535 Upstream summary: Siddharth Dushantha discovered that VTE incorrectly handled large window resize escape sequences. An attacker could possibly use this issue to consume resources, leading to […]

Read more
Ubuntu 16.04 — unbound — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — unbound — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 May 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7080-1 Related CVEs: CVE-2024-8508 CVE-2024-43167 CVE-2024-43168 CVE-2017-15105 Upstream summary: Toshifumi Sakaguchi discovered that Unbound incorrectly handled name compression for large RRsets, which could lead to excessive CPU usage. An attacker […]

Read more
CHAT