ubuntu

Ubuntu 18.04 — underscore — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — underscore — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4913-1 Related CVEs: CVE-2021-23358 Upstream summary: It was discovered that Underscore incorrectly handled certain inputs. An attacker could possibly use this issue to inject arbitrary code. Table of contents Symptom […]

Read more
Ubuntu 16.04 — wireshark — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — wireshark — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 February 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7552-1 Related CVEs: CVE-2021-4185 CVE-2022-0582 CVE-2022-0586 CVE-2022-3190 CVE-2021-4182 CVE-2022-0585 CVE-2021-39929 CVE-2021-4186  +12 more Upstream summary: It was discovered that Wireshark did not correctly handle recursion. If a user or system […]

Read more
Ubuntu 18.04 — ruby-sinatra — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — ruby-sinatra — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7664-1 Related CVEs: CVE-2022-29970 CVE-2022-45442 Upstream summary: It was discovered that Sinatra incorrectly handled serving static files. An attacker could possibly use this issue to perform local file inclusion, obtaining […]

Read more
Ubuntu 20.04 — ruby-sinatra — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — ruby-sinatra — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7664-1 Related CVEs: CVE-2022-29970 CVE-2022-45442 Upstream summary: It was discovered that Sinatra incorrectly handled serving static files. An attacker could possibly use this issue to perform local file inclusion, obtaining […]

Read more
Ubuntu 20.04 — golang-1.13 — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — golang-1.13 — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6038-2 Related CVEs: CVE-2022-1705 CVE-2022-27664 CVE-2022-28131 CVE-2022-2879 CVE-2022-2880 CVE-2022-29526 CVE-2022-30629 CVE-2022-30630  +11 more Upstream summary: USN-6038-1 fixed several vulnerabilities in Go 1.18. This update provides the corresponding updates for Go […]

Read more
Ubuntu 20.04 — digikam — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — digikam — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 February 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7266-1 Related CVEs: CVE-2017-0691 CVE-2020-19858 CVE-2020-22628 CVE-2020-35530 CVE-2020-35531 CVE-2020-35532 CVE-2020-35533 CVE-2021-32142  +1 more Upstream summary: Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in digiKam, did […]

Read more
Ubuntu 16.04 — privoxy — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — privoxy — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 February 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4886-1 Related CVEs: CVE-2020-35502 CVE-2021-20209 CVE-2021-20210 CVE-2021-20211 CVE-2021-20212 CVE-2021-20213 CVE-2021-20214 CVE-2021-20215  +6 more Upstream summary: It was discovered that Privoxy incorrectly handled CGI requests. An attacker could possibly use this […]

Read more
Ubuntu 16.04 — php-pear — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — php-pear — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5027-2 Related CVEs: CVE-2021-32610 CVE-2020-36193 CVE-2020-28948 CVE-2020-28949 CVE-2018-1000888 Upstream summary: USN-5027-1 fixed a vulnerability in PEAR. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It […]

Read more
Ubuntu 16.04 — scilab — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — scilab — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5061-1 Related CVEs: CVE-2021-30485 CVE-2021-31229 CVE-2021-31347 CVE-2021-31598 Upstream summary: It was discovered that Scilab did not properly sanitize XML inputs. An atacker could use a crafted XML file to cause […]

Read more
Common Problems 117965

Ubuntu 18.04 LTS – hostname and FQDN mismatch causes sudo delay

🟡 Medium   ⏱ 5–30 min  Last verified: 8 February 2022 Affected versions: Ubuntu 18.04 LTS Ubuntu 18.04 Ubuntu 18.04.6 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention […]

Read more
CHAT