ubuntu

Ubuntu 18.04 — openconnect — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — openconnect — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4565-1 Related CVEs: CVE-2019-16239 Upstream summary: It was discovered that OpenConnect has a buffer overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes. An attacker could […]

Read more
Ubuntu 14.04 — quagga — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — quagga — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 May 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3573-1 Related CVEs: CVE-2018-5378 CVE-2018-5379 CVE-2018-5380 CVE-2018-5381 CVE-2017-16227 CVE-2017-5495 CVE-2016-1245 CVE-2016-4036  +3 more Upstream summary: It was discovered that a double-free vulnerability existed in the Quagga BGP daemon when processing […]

Read more
Ubuntu 18.04 — gradle — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — gradle — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 May 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4858-1 Related CVEs: CVE-2019-11065 CVE-2019-16370 Upstream summary: It was discovered that Gradle used an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins were used. […]

Read more
Ubuntu 14.04 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libreoffice — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 May 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3883-1 Related CVEs: CVE-2018-10119 CVE-2018-10120 CVE-2018-10583 CVE-2018-11790 CVE-2018-16858 CVE-2018-6871 CVE-2017-12607 CVE-2017-12608  +12 more Upstream summary: It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked […]

Read more
Ubuntu 18.04 — hdf5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — hdf5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 May 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5272-1 Related CVEs: CVE-2018-17233 CVE-2018-17234 CVE-2018-17237 CVE-2017-17505 CVE-2017-17506 CVE-2017-17508 Upstream summary: It was discovered that HDF5 incorrectly handled certain inputs. An attacker could possibly use this issue to cause a […]

Read more
Ubuntu 16.04 — tnef — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — tnef — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 May 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4524-1 Related CVEs: CVE-2019-18849 Upstream summary: Paul Dreik discovered that TNEF incorrectly handled filenames. If a user were tricked into opening a specially crafted email attachment, an attacker could possibly […]

Read more
Ubuntu 16.04 — afflib — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — afflib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 May 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6518-1 Related CVEs: CVE-2018-8050 Upstream summary: Luis Rocha discovered that AFFLIB incorrectly handled certain input files. If a user or automated system were tricked into processing a specially crafted AFF […]

Read more
Ubuntu 16.04 — gettext — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gettext — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 May 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3815-1 Related CVEs: CVE-2018-18751 Upstream summary: It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code. Table of contents Symptom […]

Read more
Ubuntu 14.04 — zziplib — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — zziplib — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 May 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3699-1 Related CVEs: CVE-2018-6381 CVE-2018-6484 CVE-2018-6540 CVE-2018-6541 CVE-2018-6869 CVE-2018-7725 CVE-2018-7726 CVE-2017-5974  +6 more Upstream summary: It was discovered that zziplib incorrectly handled certain malformed ZIP files. If a user or […]

Read more
Ubuntu 18.04 — libice — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 May 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5744-1 Related CVEs: CVE-2017-2626 Upstream summary: It was discovered that libICE was using a weak mechanism to generate the session cookies. A local attacker could possibly use this issue to […]

Read more
CHAT