AWS Security Advisories · July 2015 — AWS Security Advisories
19 advisories 47 CVEs 3 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2015-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2015-569

ALAS · AL1Weaponized exploitMedium2015-07-22

ALAS-2015-569: nss, nss-util (medium)

CVEs:CVE-2015-4000

Affected products

ProductStatusVendorPackageEcosystem
nss, nss-util affected Amazon nss, nss-util
Upstream advisory

ALAS-2015-573

ALAS · AL1Weaponized exploitCritical2015-07-28

ALAS-2015-573: bind (critical)

CVEs:CVE-2015-5477

Affected products

ProductStatusVendorPackageEcosystem
bind affected Amazon bind
Upstream advisory

ALAS-2015-564

ALAS · AL1Weaponized exploitCritical2015-07-09

ALAS-2015-564: openssl (critical)

CVEs:CVE-2015-1793

Affected products

ProductStatusVendorPackageEcosystem
openssl affected Amazon openssl
Upstream advisory

ALAS-2015-567

ALAS · AL1EPSS <= 49%Medium2015-07-22

ALAS-2015-567: 389-ds-base (medium)

CVEs:CVE-2015-3230

Affected products

ProductStatusVendorPackageEcosystem
389-ds-base affected Amazon 389-ds-base
Upstream advisory

ALAS-2015-560

ALAS · AL1EPSS <= 49%Medium2015-07-07

ALAS-2015-560: php-ZendFramework (medium)

CVEs:CVE-2015-3154

Affected products

ProductStatusVendorPackageEcosystem
php-ZendFramework affected Amazon php-ZendFramework
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.