ubuntu

Ubuntu 16.04 — libidn2-0 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libidn2-0 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 January 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3421-2 Related CVEs: CVE-2017-14062 Upstream summary: USN-3421-1 fixed a vulnerability in Libidn2. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Table of contents Symptom […]

Read more
Ubuntu 14.04 — miniupnpc — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — miniupnpc — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 January 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3562-1 Related CVEs: CVE-2017-1000494 CVE-2017-8798 CVE-2015-6031 CVE-2014-3985 Upstream summary: It was discovered that MiniUPnP incorrectly handled memory. A remote attacker could use this issue to cause a denial of service […]

Read more
Ubuntu 14.04 — gnutls26 — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — gnutls26 — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 January 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3318-1 Related CVEs: CVE-2017-7507 CVE-2017-7869 CVE-2016-8610 CVE-2016-7444 CVE-2017-5334 CVE-2017-5335 CVE-2017-5336 CVE-2017-5337  +7 more Upstream summary: Hubert Kario discovered that GnuTLS incorrectly handled decoding a status response TLS extension. A remote […]

Read more
Ubuntu 14.04 — libxdmcp — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libxdmcp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 January 2018 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5690-1 Related CVEs: CVE-2017-2625 Upstream summary: It was discovered that libXdmcp was generating weak session keys. A local attacker could possibly use this issue to perform a brute force attack […]

Read more
Ubuntu 16.04 — cvs — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — cvs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3399-1 Related CVEs: CVE-2017-12836 Upstream summary: Hank Leininger discovered that cvs did not properly handle SSH for remote repositories. A remote attacker could use this to construct a cvs repository […]

Read more
Ubuntu 16.04 — libquicktime — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libquicktime — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4545-1 Related CVEs: CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125 CVE-2017-9126 CVE-2017-9127 CVE-2017-9128 Upstream summary: It was discovered that libquicktime incorrectly handled certain malformed MP4 files. If a user were tricked into opening […]

Read more
Ubuntu 14.04 — puppet — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — puppet — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 December 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3567-1 Related CVEs: CVE-2017-10689 CVE-2014-3248 CVE-2017-2295 Upstream summary: It was discovered that Puppet incorrectly handled permissions when unpacking certain tarballs. A local user could possibly use this issue to execute […]

Read more
Ubuntu 16.04 — oxide-qt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — oxide-qt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 December 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3236-1 Related CVEs: CVE-2017-5029 CVE-2017-5030 CVE-2017-5031 CVE-2017-5033 CVE-2017-5035 CVE-2017-5037 CVE-2017-5040 CVE-2017-5041  +12 more Upstream summary: Multiple vulnerabilities were discovered in Chromium. If a user were tricked in to opening a […]

Read more
Ubuntu 16.04 — keystone — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — keystone — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3448-1 Related CVEs: CVE-2017-2673 Upstream summary: Boris Bobrov discovered that OpenStack Keystone incorrectly handled federation mapping when there are rules in which group-based assignments are not used. A remote authenticated […]

Read more
Ubuntu 14.04 — libxcursor — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libxcursor — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 December 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3729-1 Related CVEs: CVE-2015-9262 CVE-2017-16612 Upstream summary: It was discovered that libxcursor incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. Table […]

Read more
CHAT