ubuntu

Ubuntu 16.04 — gunicorn — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gunicorn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4022-1 Related CVEs: CVE-2018-1000164 Upstream summary: It was discovered that gunicorn improperly handled certain input. An attacker could potentially use this issue execute a cross-site scripting (XSS) attack. Table of […]

Read more
Ubuntu 16.04 — zipios++ — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — zipios++ — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4057-1 Related CVEs: CVE-2019-13453 Upstream summary: Mike Salvatore discovered that Zipios mishandled certain malformed ZIP files. An attacker could use this vulnerability to cause a denial of service or consume […]

Read more
Ubuntu 16.04 — libapache2-mod-auth-mellon — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libapache2-mod-auth-mellon — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4597-1 Related CVEs: CVE-2017-6807 CVE-2019-3877 CVE-2019-3878 Upstream summary: François Kooman discovered that mod_auth_mellon incorrectly handled cookies. An attacker could possibly use this issue to cause a Cross-Site Session Transfer attack. […]

Read more
Ubuntu 18.04 — file — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — file — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 April 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3911-2 Related CVEs: https://launchpad.net/bugs/1835596 CVE-2019-18218 CVE-2019-8904 CVE-2019-8905 CVE-2019-8906 CVE-2019-8907 CVE-2014-9620 CVE-2014-9621  +3 more Upstream summary: USN-3911-1 fixed vulnerabilities in file. One of the backported security fixes introduced a regression that […]

Read more
Ubuntu 16.04 — bash — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — bash — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5380-1 Related CVEs: CVE-2019-18276 CVE-2019-9924 CVE-2016-0634 CVE-2016-7543 CVE-2016-9401 CVE-2017-5932 Upstream summary: It was discovered that Bash did not properly drop privileges when the binary had the setuid bit enabled. An […]

Read more
Ubuntu 18.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 April 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4778-1 Related CVEs: CVE-2015-8869 CVE-2018-9838 Upstream summary: It was discovered that OCaml mishandled sign extensions. A remote attacker could use this vulnerability to steal sensitive information, cause a denial of […]

Read more
Ubuntu 16.04 — nfs-utils — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — nfs-utils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4400-1 Related CVEs: CVE-2019-3689 Upstream summary: It was discovered that the nfs-utils package set incorrect permissions on the /var/lib/nfs directory. An attacker could possibly use this issue to escalate privileges. […]

Read more
Ubuntu 14.04 — libonig — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libonig — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 April 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5662-1 Related CVEs: CVE-2019-16163 CVE-2019-19012 CVE-2019-19203 CVE-2019-19204 CVE-2019-19246 Upstream summary: It was discovered that Oniguruma incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a […]

Read more
Ubuntu 18.04 — flask — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — flask — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4378-1 Related CVEs: CVE-2018-1000656 Upstream summary: It was discovered that Flask incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. Table of […]

Read more
Ubuntu 16.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ntp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4229-1 Related CVEs: CVE-2018-12327 CVE-2018-7182 CVE-2018-7183 CVE-2018-7184 CVE-2018-7185 CVE-2016-2519 CVE-2016-7426 CVE-2016-7427  +12 more Upstream summary: It was discovered that ntpq and ntpdc incorrectly handled some arguments. An attacker could possibly […]

Read more
CHAT