ubuntu

Ubuntu 16.04 — tomcat6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — tomcat6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 October 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3081-2 Related CVEs: CVE-2016-1240 CVE-2016-0762 CVE-2016-5018 CVE-2016-6794 CVE-2016-6796 CVE-2016-6797 CVE-2016-6816 CVE-2016-8735 Upstream summary: Dawid Golunski discovered that the Tomcat init script incorrectly handled creating log files. A remote attacker could […]

Read more
Ubuntu 16.04 — gifsicle — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gifsicle — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 October 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4803-1 Related CVEs: CVE-2017-1000421 CVE-2017-18120 Upstream summary: It was discovered that Gifsicle did not properly handle certain input. If a user were tricked into opening a malicious GIF, an attacker […]

Read more
Ubuntu 14.04 — munin — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — munin — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 October 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3215-2 Related CVEs: https://launchpad.net/bugs/1669764 CVE-2017-6188 Upstream summary: USN-3215-1 fixed a vulnerability in Munin. The upstream patch caused a regression leading to errors being appended to the log file. This update […]

Read more
Ubuntu 16.04 — libusbmuxd — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libusbmuxd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 October 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3026-2 Related CVEs: CVE-2016-5104 Upstream summary: It was discovered that libusbmuxd incorrectly handled socket permissions. A remote attacker could use this issue to access services on iOS devices, contrary to […]

Read more
Ubuntu 16.04 — phpmyadmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — phpmyadmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 October 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4843-1 Related CVEs: CVE-2014-9218 CVE-2016-6609 CVE-2016-6619 CVE-2016-6630 CVE-2016-9849 CVE-2016-9866 CVE-2017-18264 CVE-2017-1000014  +12 more Upstream summary: Javier Nieto and Andres Rojas discovered that phpMyAdmin incorrectly managed input in the form of […]

Read more
Ubuntu 14.04 — juju-core — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — juju-core — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 October 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3300-1 Related CVEs: CVE-2017-9232 Upstream summary: Ryan Beisner discovered juju did not set permissions on a Unix domain socket. A local attacker could use this flaw to gain administrative privileges. […]

Read more
Ubuntu 16.04 — libapache2-mod-perl2 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libapache2-mod-perl2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 October 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3825-1 Related CVEs: CVE-2011-2767 Upstream summary: Jan Ingvoldstad discovered that mod_perl incorrectly handled configuration options to disable being used by unprivileged users, contrary to the documentation. A local attacker could […]

Read more
Ubuntu 14.04 — libdbd-mysql-perl — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libdbd-mysql-perl — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 October 2017 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7417-1 Related CVEs: CVE-2016-1249 CVE-2016-1251 CVE-2017-10788 CVE-2017-10789 CVE-2014-9906 CVE-2015-8949 CVE-2016-1246 Upstream summary: It was discovered that libdbd-mysql-perl did not correctly handle certain SQL queries. An attacker could possibly use this […]

Read more
Ubuntu 16.04 — lightdm — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — lightdm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 September 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3255-1 Related CVEs: CVE-2017-7358 Upstream summary: It was discovered that LightDM incorrectly handled home directory creation for guest users. A local attacker could use this issue to gain ownership of […]

Read more
Ubuntu 16.04 — node-tar — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — node-tar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 September 2017 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4777-1 Related CVEs: CVE-2015-8860 Upstream summary: It was discovered that node-tar mishandled certain tar archives. An attacker could use this vulnerability to write arbitrary files to the filesystem. Table of […]

Read more
CHAT