ubuntu

Ubuntu 16.04 — amd64-microcode — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — amd64-microcode — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7077-1 Related CVEs: CVE-2023-31315 CVE-2023-20569 CVE-2023-20593 CVE-2017-5715 Upstream summary: Enrique Nissim and Krzysztof Okupski discovered that some AMD processors did not properly restrict access to the System Management Mode (SMM) […]

Read more
Ubuntu 14.04 — open-vm-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — open-vm-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 April 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7714-1 Related CVEs: CVE-2023-34059 CVE-2014-4199 Upstream summary: Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to […]

Read more
Ubuntu 14.04 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 March 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6885-5 Related CVEs: CVE-2024-38474 CVE-2024-38475 CVE-2023-31122 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522  +12 more Upstream summary: USN-6885-1 fixed vulnerabilities in Apache. This update provides the corresponding updates for Ubuntu 14.04 LTS. […]

Read more
Ubuntu 20.04 — freeradius — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — freeradius — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7055-1 Related CVEs: CVE-2024-3596 CVE-2019-17185 CVE-2022-41860 CVE-2022-41861 Upstream summary: Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc Stevens, and Adam Suhl discovered that FreeRADIUS incorrectly authenticated certain responses. […]

Read more
Ubuntu 16.04 — libjettison-java — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libjettison-java — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 March 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6179-1 Related CVEs: CVE-2023-1436 CVE-2022-40149 CVE-2022-40150 CVE-2022-45685 CVE-2022-45693 Upstream summary: It was discovered that Jettison incorrectly handled certain inputs. If a user or an automated system were tricked into opening […]

Read more
Ubuntu 16.04 — gpac — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gpac — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 March 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7320-1 Related CVEs: CVE-2023-5520 CVE-2024-0321 CVE-2024-0322 CVE-2018-1000100 CVE-2018-13005 CVE-2018-13006 CVE-2018-20760 CVE-2018-20761  +3 more Upstream summary: It was discovered that the GPAC MP4Box utility incorrectly handled certain AC3 files, which could […]

Read more
Ubuntu 20.04 — c-ares — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — c-ares — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 March 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6676-1 Related CVEs: CVE-2024-25629 CVE-2020-22217 CVE-2023-31130 CVE-2023-32067 CVE-2022-4904 CVE-2021-3672 Upstream summary: Vojtěch Vobr discovered that c-ares incorrectly handled user input from local configuration files. An attacker could possibly use this […]

Read more
Ubuntu 18.04 — cimg — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — cimg — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 March 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7437-1 Related CVEs: CVE-2022-1325 CVE-2024-26540 CVE-2018-7587 CVE-2018-7588 CVE-2018-7589 Upstream summary: It was discovered that the CImg library did not properly check the size of images before loading them. An attacker […]

Read more
Ubuntu 16.04 — gss-ntlmssp — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gss-ntlmssp — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7588-1 Related CVEs: CVE-2023-25567 CVE-2023-25565 CVE-2023-25564 CVE-2023-25563 Upstream summary: Phil Turnbull discovered that GSS NTLMSSP may perform out-of-bounds reads when decoding NTLM fields and target information. An attacker could possibly […]

Read more
Ubuntu 22.04 — cpdb-libs — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — cpdb-libs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 March 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6204-1 Related CVEs: CVE-2023-34095 Upstream summary: Seth Arnold discovered that CPDB incorrectly handled certain characters. An attacker could possibly use this issue to cause a crash or execute arbitrary code. […]

Read more
CHAT