ubuntu

Ubuntu 14.04 — pillow — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — pillow — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8135-1 Related CVEs: CVE-2023-50447 CVE-2021-28675 CVE-2021-25290 CVE-2021-25288 CVE-2021-28676 CVE-2023-44271 CVE-2021-28677 CVE-2021-25287  +12 more Upstream summary: It was discovered that Pillow did not correctly handle reading J2K files, which could lead […]

Read more
Ubuntu 18.04 — liblouis — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — liblouis — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 April 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5996-1 Related CVEs: CVE-2023-26767 CVE-2023-26768 CVE-2023-26769 CVE-2022-26981 CVE-2022-31783 CVE-2018-12085 CVE-2018-17294 CVE-2018-11683  +5 more Upstream summary: It was discovered that Liblouis incorrectly handled certain files. An attacker could possibly use this […]

Read more
Ubuntu 22.04 — gawk — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — gawk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6373-1 Related CVEs: CVE-2023-4156 Upstream summary: It was discovered that gawk could be made to read out of bounds when processing certain inputs. If a user or an automated system […]

Read more
Ubuntu 20.04 — python-asyncssh — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — python-asyncssh — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 April 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7108-1 Related CVEs: CVE-2023-46445 CVE-2023-46446 CVE-2023-48795 Upstream summary: Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that AsyncSSH did not properly handle the extension info message. An attacker able to […]

Read more
Ubuntu 22.04 — mosquitto — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — mosquitto — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 April 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7441-1 Related CVEs: CVE-2024-10525 CVE-2024-3935 CVE-2021-34431 CVE-2021-34434 CVE-2021-41039 CVE-2023-0809 CVE-2023-28366 CVE-2023-3592 Upstream summary: It was discovered that Eclipse Mosquitto client incorrectly handled memory when receiving a SUBACK packet. An attacker […]

Read more
Ubuntu 16.04 — libwebp — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libwebp — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6078-2 Related CVEs: CVE-2023-1999 CVE-2018-25009 CVE-2018-25010 CVE-2018-25011 CVE-2018-25012 CVE-2018-25013 CVE-2018-25014 CVE-2020-36328  +3 more Upstream summary: USN-6078-1 fixed a vulnerability in libwebp. This update provides the corresponding update for Ubuntu 16.04 […]

Read more
Ubuntu 20.04 — librsvg — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — librsvg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6266-1 Related CVEs: CVE-2023-38633 Upstream summary: Zac Sims discovered that librsvg incorrectly handled decoding URLs. A remote attacker could possibly use this issue to read arbitrary files by using an […]

Read more
Ubuntu 20.04 — composer — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — composer — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7603-1 Related CVEs: CVE-2024-35241 CVE-2024-35242 CVE-2024-24821 CVE-2023-43655 CVE-2022-24828 CVE-2021-29472 Upstream summary: Thomas Chauchefoin discovered that Composer did not correctly handle certain arguments. An attacker could possibly use this issue to […]

Read more
Ubuntu 22.04 — composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7603-1 Related CVEs: CVE-2024-35241 CVE-2024-35242 CVE-2024-24821 CVE-2023-43655 CVE-2022-24828 Upstream summary: Thomas Chauchefoin discovered that Composer did not correctly handle certain arguments. An attacker could possibly use this issue to execute […]

Read more
Ubuntu 14.04 — gawk — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — gawk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6373-1 Related CVEs: CVE-2023-4156 Upstream summary: It was discovered that gawk could be made to read out of bounds when processing certain inputs. If a user or an automated system […]

Read more
CHAT