ubuntu

Ubuntu 20.04 — nvidia-graphics-drivers-515 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — nvidia-graphics-drivers-515 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5547-1 Related CVEs: CVE-2022-31607 CVE-2022-31608 CVE-2022-31615 Upstream summary: Le Wu discovered that the NVIDIA graphics drivers did not properly perform input validation in some situations. A local user could use […]

Read more
Ubuntu 20.04 — node-xmldom — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — node-xmldom — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6102-1 Related CVEs: CVE-2021-21366 CVE-2022-37616 CVE-2022-39353 Upstream summary: It was discovered that xmldom incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially […]

Read more
Ubuntu 22.04 — py7zr — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — py7zr — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 June 2023 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7030-1 Related CVEs: CVE-2022-44900 Upstream summary: It was discovered that py7zr was vulnerable to path traversal attacks. If a user or automated system were tricked into extracting a specially crafted […]

Read more
Ubuntu 22.04 — xrdp — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — xrdp — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 June 2023 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6474-1 Related CVEs: CVE-2022-23468 CVE-2022-23477 CVE-2022-23478 CVE-2022-23479 CVE-2022-23480 CVE-2022-23481 CVE-2022-23482 CVE-2022-23483  +5 more Upstream summary: It was discovered that xrdp incorrectly handled validation of client-supplied data, which could lead to […]

Read more
Ubuntu 18.04 — node-css-what — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — node-css-what — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 May 2023 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6065-1 Related CVEs: CVE-2021-33587 CVE-2022-21222 Upstream summary: It was discovered that css-what incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted […]

Read more
Ubuntu 16.04 — golang-yaml.v2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — golang-yaml.v2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 May 2023 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6287-1 Related CVEs: CVE-2021-4235 CVE-2022-3064 Upstream summary: Simon Ferquel discovered that the Go yaml package incorrectly handled certain YAML documents. If a user or an automated system were tricked into […]

Read more
Ubuntu 16.04 — awstats — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — awstats — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 May 2023 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5899-1 Related CVEs: CVE-2022-46391 CVE-2017-1000501 CVE-2020-29600 CVE-2020-35176 Upstream summary: It was discovered that AWStats did not properly sanitize the content of whois responses in the hostinfo plugin. An attacker could […]

Read more
Ubuntu 22.04 — tar — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — tar — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 May 2023 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6543-1 Related CVEs: CVE-2023-39804 CVE-2022-48303 Upstream summary: It was discovered that tar incorrectly handled extended attributes in PAX archives. An attacker could use this issue to cause tar to crash, […]

Read more
CHAT