AWS Security Advisories · April 2018 — AWS Security Advisories
17 advisories 51 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2018-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2018-988

ALAS · AL1Weaponized exploitMedium2018-04-05

ALAS-2018-988: php70, php56 (medium)

CVEs:CVE-2018-7584

Affected products

ProductStatusVendorPackageEcosystem
php70, php56 affected Amazon php70, php56
Upstream advisory

ALAS-2018-989

ALAS · AL1Weaponized exploitCritical2018-04-05

ALAS-2018-989: python-paramiko (critical)

CVEs:CVE-2018-7750

Affected products

ProductStatusVendorPackageEcosystem
python-paramiko affected Amazon python-paramiko
Upstream advisory

ALAS-2018-990

ALAS · AL1PoC exploitMedium2018-04-05

ALAS-2018-990: postgresql93, postgresql94, postgresql95, postgresql96 (medium)

CVEs:CVE-2018-1058

Affected products

ProductStatusVendorPackageEcosystem
postgresql93, postgresql94, postgresql95, postgresql96 affected Amazon postgresql93, postgresql94, postgresql95, postgresql96
Upstream advisory

ALAS-2018-981

ALAS · AL1PoC exploitCritical2018-04-05

ALAS-2018-981: libvorbis (critical)

CVEs:CVE-2018-5146

Affected products

ProductStatusVendorPackageEcosystem
libvorbis affected Amazon libvorbis
Upstream advisory

ALAS-2018-1003

ALAS · AL1PoC exploitMedium2018-04-26

ALAS-2018-1003: python34, python35, python36, python27 (medium)

CVEs:CVE-2018-1060CVE-2018-1061

Affected products

ProductStatusVendorPackageEcosystem
python34, python35, python36, python27 affected Amazon python34, python35, python36, python27
Upstream advisory

ALAS-2018-987

ALAS · AL1EPSS <= 49%Medium2018-04-26

ALAS-2018-987: mod24_wsgi (medium)

CVEs:CVE-2014-8583

Affected products

ProductStatusVendorPackageEcosystem
mod24_wsgi affected Amazon mod24_wsgi
Upstream advisory

ALAS-2018-997

ALAS · AL1All remainingMedium2018-04-19

ALAS-2018-997: exim (medium)

Affected products

ProductStatusVendorPackageEcosystem
exim affected Amazon exim
Upstream advisory

ALAS-2018-996

ALAS · AL1All remainingMedium2018-04-19

ALAS-2018-996: stunnel, amazon-efs-utils (medium)

Affected products

ProductStatusVendorPackageEcosystem
stunnel, amazon-efs-utils affected Amazon stunnel, amazon-efs-utils
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.