AWS Security Advisories · August 2017 — AWS Security Advisories
28 advisories 97 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2017-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2017-883

ALAS · AL1Weaponized exploitImportant2017-08-31

ALAS-2017-883: subversion, mod_dav_svn (important)

CVEs:CVE-2017-9800

Affected products

ProductStatusVendorPackageEcosystem
subversion, mod_dav_svn affected Amazon subversion, mod_dav_svn
Upstream advisory

ALAS-2017-886

ALAS · AL1Weaponized exploitImportant2017-08-31

ALAS-2017-886: aws-cfn-bootstrap (important)

CVEs:CVE-2017-9450

Affected products

ProductStatusVendorPackageEcosystem
aws-cfn-bootstrap affected Amazon aws-cfn-bootstrap
Upstream advisory

ALAS-2017-884

ALAS · AL1PoC exploitMedium2017-08-31

ALAS-2017-884: postgresql93, postgresql92 (medium)

CVEs:CVE-2017-7546CVE-2017-7547

Affected products

ProductStatusVendorPackageEcosystem
postgresql93, postgresql92 affected Amazon postgresql93, postgresql92
Upstream advisory

ALAS-2017-875

ALAS · AL1EPSS <= 49%Medium2017-08-30

ALAS-2017-875: authconfig (medium)

CVEs:CVE-2017-7488

Affected products

ProductStatusVendorPackageEcosystem
authconfig affected Amazon authconfig
Upstream advisory

ALAS-2017-864

ALAS · AL1EPSS <= 49%Medium2017-08-03

ALAS-2017-864: libtommath, libtomcrypt (medium)

CVEs:CVE-2016-6129

Affected products

ProductStatusVendorPackageEcosystem
libtommath, libtomcrypt affected Amazon libtommath, libtomcrypt
Upstream advisory

ALAS-2017-866

ALAS · AL1All remainingImportant2017-08-03

ALAS-2017-866: aws-cfn-bootstrap (important)

Affected products

ProductStatusVendorPackageEcosystem
aws-cfn-bootstrap affected Amazon aws-cfn-bootstrap
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.