AWS Security Advisories · October 2018 — AWS Security Advisories
11 advisories 19 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2018-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

ALAS-2018-1096

ALAS · AL1Critical2018-10-23

ALAS-2018-1096: python-paramiko (critical)

CVEs:CVE-2018-1000805

Affected products

ProductStatusVendorPackageEcosystem
python-paramiko affected Amazon python-paramiko
Upstream advisory

ALAS-2018-1090

ALAS · AL1Medium2018-10-17

ALAS-2018-1090: php56, php70, php71, php72 (medium)

CVEs:CVE-2018-17082

Affected products

ProductStatusVendorPackageEcosystem
php56, php70, php71, php72 affected Amazon php56, php70, php71, php72
Upstream advisory

ALAS-2018-1085

ALAS · AL1Important2018-10-03

ALAS-2018-1085: mod_perl, mod24_perl (important)

CVEs:CVE-2011-2767

Affected products

ProductStatusVendorPackageEcosystem
mod_perl, mod24_perl affected Amazon mod_perl, mod24_perl
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.