AWS Security Advisories · December 2013 — AWS Security Advisories
22 advisories 64 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2013-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2013-249

ALAS · AL1ExploitedCISA KEV listedImportant2013-12-02

ALAS-2013-249: nginx (important)

CVEs:CVE-2013-4547

Affected products

ProductStatusVendorPackageEcosystem
nginx affected Amazon nginx
Upstream advisory

ALAS-2013-263

ALAS · AL1Weaponized exploitCritical2013-12-17

ALAS-2013-263: php54 (critical)

CVEs:CVE-2013-6420

Affected products

ProductStatusVendorPackageEcosystem
php54 affected Amazon php54
Upstream advisory

ALAS-2013-264

ALAS · AL1Weaponized exploitCritical2013-12-17

ALAS-2013-264: php55 (critical)

CVEs:CVE-2013-6420

Affected products

ProductStatusVendorPackageEcosystem
php55 affected Amazon php55
Upstream advisory

ALAS-2013-251

ALAS · AL1EPSS <= 49%Medium2013-12-02

ALAS-2013-251: wireshark (medium)

CVEs:CVE-2012-2392CVE-2012-3825CVE-2012-4285CVE-2012-4288CVE-2012-4289CVE-2012-4290CVE-2012-4291CVE-2012-4292CVE-2012-5595CVE-2012-5597CVE-2012-5598CVE-2012-5599CVE-2012-5600CVE-2012-6056CVE-2012-6059CVE-2012-6060CVE-2012-6061CVE-2012-6062CVE-2013-3557CVE-2013-3559CVE-2013-3561CVE-2013-4081CVE-2013-4083CVE-2013-4927CVE-2013-4931CVE-2013-4932CVE-2013-4933CVE-2013-4934CVE-2013-4935CVE-2013-4936CVE-2013-5721

Affected products

ProductStatusVendorPackageEcosystem
wireshark affected Amazon wireshark
Upstream advisory

ALAS-2013-254

ALAS · AL1EPSS <= 49%Medium2013-12-03

ALAS-2013-254: mod24_nss (medium)

CVEs:CVE-2013-4566

Affected products

ProductStatusVendorPackageEcosystem
mod24_nss affected Amazon mod24_nss
Upstream advisory

ALAS-2013-255

ALAS · AL1EPSS <= 49%Important2013-12-11

ALAS-2013-255: 389-ds-base (important)

CVEs:CVE-2013-4485

Affected products

ProductStatusVendorPackageEcosystem
389-ds-base affected Amazon 389-ds-base
Upstream advisory

ALAS-2013-260

ALAS · AL1EPSS <= 49%Low2013-12-11

ALAS-2013-260: xorg-x11-server (low)

CVEs:CVE-2013-1940

Affected products

ProductStatusVendorPackageEcosystem
xorg-x11-server affected Amazon xorg-x11-server
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.