AWS Security Advisories · October 2011 — AWS Security Advisories
16 advisories 39 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2011-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2011-4

ALAS · AL1PoC exploitMedium2011-10-10

ALAS-2011-4: openssl (medium)

CVEs:CVE-2011-3207

Affected products

ProductStatusVendorPackageEcosystem
openssl affected Amazon openssl
Upstream advisory

ALAS-2011-12

ALAS · AL1PoC exploitMedium2011-10-31

ALAS-2011-12: postgresql (medium)

CVEs:CVE-2011-2483

Affected products

ProductStatusVendorPackageEcosystem
postgresql affected Amazon postgresql
Upstream advisory

ALAS-2011-5

ALAS · AL1EPSS <= 49%Medium2011-10-10

ALAS-2011-5: perl-FCGI (medium)

CVEs:CVE-2011-2766

Affected products

ProductStatusVendorPackageEcosystem
perl-FCGI affected Amazon perl-FCGI
Upstream advisory

ALAS-2011-2

ALAS · AL1EPSS <= 49%Important2011-10-10

ALAS-2011-2: cyrus-imapd (important)

CVEs:CVE-2011-3208

Affected products

ProductStatusVendorPackageEcosystem
cyrus-imapd affected Amazon cyrus-imapd
Upstream advisory

ALAS-2011-17

ALAS · AL1EPSS <= 49%Medium2011-10-31

ALAS-2011-17: perl-libwww-perl (medium)

CVEs:CVE-2011-0633

Affected products

ProductStatusVendorPackageEcosystem
perl-libwww-perl affected Amazon perl-libwww-perl
Upstream advisory

ALAS-2011-8

ALAS · AL1EPSS <= 49%Important2011-10-31

ALAS-2011-8: freetype (important)

CVEs:CVE-2011-3256

Affected products

ProductStatusVendorPackageEcosystem
freetype affected Amazon freetype
Upstream advisory

ALAS-2011-6

ALAS · AL1EPSS <= 49%Medium2011-10-10

ALAS-2011-6: openswan (medium)

CVEs:CVE-2011-3380

Affected products

ProductStatusVendorPackageEcosystem
openswan affected Amazon openswan
Upstream advisory

ALAS-2011-3

ALAS · AL1All remainingMedium2011-10-10

ALAS-2011-3: ca-certificates (medium)

Affected products

ProductStatusVendorPackageEcosystem
ca-certificates affected Amazon ca-certificates
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.