ALAS-2017-852
ALAS-2017-852: openvpn (important)
CVEs:CVE-2017-7508CVE-2017-7520CVE-2017-7521CVE-2017-7522
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openvpn | affected | Amazon | openvpn | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
ALAS-2017-852: openvpn (important)
CVEs:CVE-2017-7508CVE-2017-7520CVE-2017-7521CVE-2017-7522
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| openvpn | affected | Amazon | openvpn | — |
ALAS-2017-851: httpd (medium)
CVEs:CVE-2016-8743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| httpd | affected | Amazon | httpd | — |
ALAS-2017-850: curl (low)
CVEs:CVE-2017-7407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| curl | affected | Amazon | curl | — |
ALAS-2017-849: puppet3 (important)
CVEs:CVE-2017-2295
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| puppet3 | affected | Amazon | puppet3 | — |
ALAS-2017-848: nss (important)
CVEs:CVE-2017-7502
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nss | affected | Amazon | nss | — |
ALAS-2017-847: lynis (medium)
CVEs:CVE-2017-8108
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| lynis | affected | Amazon | lynis | — |
ALAS-2017-846: kernel (medium)
CVEs:CVE-2017-8890CVE-2017-9059CVE-2017-9074CVE-2017-9075CVE-2017-9076CVE-2017-9077CVE-2017-9242
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2017-845: kernel (critical)
CVEs:CVE-2017-1000364CVE-2017-1000371
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2017-844: glibc (critical)
CVEs:CVE-2017-1000366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| glibc | affected | Amazon | glibc | — |
ALAS-2017-843: sudo (important)
CVEs:CVE-2017-1000367
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| sudo | affected | Amazon | sudo | — |
ALAS-2017-842: git (medium)
CVEs:CVE-2017-8386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| git | affected | Amazon | git | — |
ALAS-2017-841: rpcbind (important)
CVEs:CVE-2017-8779
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| rpcbind | affected | Amazon | rpcbind | — |
ALAS-2017-840: libtirpc (important)
CVEs:CVE-2017-8779
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libtirpc | affected | Amazon | libtirpc | — |
ALAS-2017-838: postgresql92 (medium)
CVEs:CVE-2017-7484CVE-2017-7486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| postgresql92 | affected | Amazon | postgresql92 | — |
ALAS-2017-839: postgresql93, postgresql94, postgresql95 (medium)
CVEs:CVE-2017-7484CVE-2017-7485CVE-2017-7486
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| postgresql93, postgresql94, postgresql95 | affected | Amazon | postgresql93, postgresql94, postgresql95 | — |
ALAS-2017-837: ghostscript (important)
CVEs:CVE-2017-8291
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ghostscript | affected | Amazon | ghostscript | — |
ALAS-2017-836: jasper (important)
CVEs:CVE-2015-5203CVE-2015-5221CVE-2016-1024CVE-2016-10251CVE-2016-1577CVE-2016-1867CVE-2016-2089CVE-2016-2116CVE-2016-8654CVE-2016-8690CVE-2016-8691CVE-2016-8692CVE-2016-8693CVE-2016-8883CVE-2016-8884CVE-2016-8885CVE-2016-9262CVE-2016-9387CVE-2016-9388CVE-2016-9389CVE-2016-9390CVE-2016-9391CVE-2016-9392CVE-2016-9393CVE-2016-9394CVE-2016-9560CVE-2016-9583CVE-2016-9591CVE-2016-9600
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| jasper | affected | Amazon | jasper | — |
ALAS-2017-835: java-1.7.0-openjdk (medium)
CVEs:CVE-2016-5542CVE-2017-3509CVE-2017-3511CVE-2017-3526CVE-2017-3533CVE-2017-3539CVE-2017-3544
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.7.0-openjdk | affected | Amazon | java-1.7.0-openjdk | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.