[v3] Container Security Issue (CVE-2019-5736)

You are viewing a previous version of this security bulletin. For the most current version please visit: "Container Security Issue (CVE-2019-5736)". February 11, 2019 11:00 PM PST CVE Identifier: CVE-2019-5736 AWS is aware of the recently disclosed security issue which affects several open-source container management systems (CVE-2019-5736). With the exception of the AWS services listed below, no customer action is required to address this issue. Amazon Linux An updated version of More info: https://aws.amazon.com/security/security-bulletins/AWS-2019-002/v3/

[v1] Linux Kernel TCP SACK Denial of Service Issues

You are viewing a previous version of this security bulletin. For the most current version please visit: "Linux Kernel TCP SACK Denial of Service Issues". June 17, 2019 10:00AM PDT CVE Identifiers: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479 AWS is aware of three recently-disclosed issues which affect the TCP processing subsystem of the Linux kernel. Specifically, a malicious TCP client or server can transmit a specially crafted series of packets that may cause the Linux kernel of More info: https://aws.amazon.com/security/security-bulletins/AWS-2019-005/v1/

[v3] Linux Kernel TCP SACK Denial of Service Issues

Last Updated: June 17, 2019 17:00PM PDT CVE Identifiers: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479 This is an update for this issue. AWS Elastic Beanstalk Updated AWS Elastic Beanstalk Linux-based platform versions are available. Customers using Managed Platform Updates will be automatically updated to the latest platform version in their selected maintenance window with no other action required. Alternatively, customers using Managed Platform Updates may independently apply available More info: https://aws.amazon.com/security/security-bulletins/AWS-2019-005/v3/

[v2] Linux Kernel TCP SACK Denial of Service Issues

Last Updated: June 17, 2019 14:15PM PDT CVE Identifiers: CVE-2019-11477, CVE-2019-11478, CVE-2019-11479 This is an update for this issue. Updated Linux kernels for Amazon Linux are available in the Amazon Linux repositories, and updated Amazon Linux AMIs are available for use. Customers with existing EC2 instances running Amazon Linux should run the following command within each EC2 instance running Amazon Linux to ensure they receive the updated package: sudo yum update kernel As is standard More info: https://aws.amazon.com/security/security-bulletins/AWS-2019-005/v2/

pppd vulnerability CVE-2020-8597

pppd vulnerability CVE-2020-8597 Security Advisory Security Advisory Description eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response ... More info: https://support.f5.com/csp/article/K73217235?utm_source=f5support&utm_medium=RSS

DSA-4637 network-manager-ssh – security update

Kobus van Schoor discovered that network-manager-ssh, a plugin toprovide VPN integration for SSH in NetworkManager, is prone to aprivilege escalation vulnerability. A local user with privileges tomodify a connection can take advantage of this flaw to execute arbitrarycommands as root. More info: https://www.debian.org/security/2020/dsa-4637

DSA-4637 network-manager-ssh – security update

Kobus van Schoor discovered that network-manager-ssh, a plugin toprovide VPN integration for SSH in NetworkManager, is prone to aprivilege escalation vulnerability. A local user with privileges tomodify a connection can take advantage of this flaw to execute arbitrarycommands as root. More info: https://www.debian.org/security/2020/dsa-4637
Translate »