AWS Security Advisories · March 2018 — AWS Security Advisories
16 advisories 67 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2018-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2018-970

ALAS · AL1ExploitedCISA KEV listedCritical2018-03-07

ALAS-2018-970: exim (critical)

CVEs:CVE-2018-6789

Affected products

ProductStatusVendorPackageEcosystem
exim affected Amazon exim
Upstream advisory

ALAS-2018-982

ALAS · AL1Weaponized exploitImportant2018-03-27

ALAS-2018-982: php71 (important)

CVEs:CVE-2018-7584

Affected products

ProductStatusVendorPackageEcosystem
php71 affected Amazon php71
Upstream advisory

ALAS-2018-978

ALAS · AL1Weaponized exploitMedium2018-03-21

ALAS-2018-978: ruby24, ruby22, ruby23 (medium)

CVEs:CVE-2017-0903

Affected products

ProductStatusVendorPackageEcosystem
ruby24, ruby22, ruby23 affected Amazon ruby24, ruby22, ruby23
Upstream advisory

ALAS-2018-977

ALAS · AL1PoC exploitMedium2018-03-21

ALAS-2018-977: python-crypto (medium)

CVEs:CVE-2018-6594

Affected products

ProductStatusVendorPackageEcosystem
python-crypto affected Amazon python-crypto
Upstream advisory

ALAS-2018-965

ALAS · AL1EPSS <= 49%Medium2018-03-07

ALAS-2018-965: tomcat-native (medium)

CVEs:CVE-2017-15698

Affected products

ProductStatusVendorPackageEcosystem
tomcat-native affected Amazon tomcat-native
Upstream advisory

ALAS-2018-968

ALAS · AL1EPSS <= 49%Medium2018-03-07

ALAS-2018-968: mod_auth_mellon, mod24_auth_mellon (medium)

CVEs:CVE-2017-6807

Affected products

ProductStatusVendorPackageEcosystem
mod_auth_mellon, mod24_auth_mellon affected Amazon mod_auth_mellon, mod24_auth_mellon
Upstream advisory

ALAS-2018-971

ALAS · AL1EPSS <= 49%Important2018-03-16

ALAS-2018-971: kernel (important)

CVEs:CVE-2018-1068

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Amazon kernel
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.