2019 - Page 555 of 572

Arch Linux — lib32-libtasn1 — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — lib32-libtasn1 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201706-10 Related CVEs: CVE-2017-6891 Upstream summary: Type: arbitrary code execution. Status: Fixed. Affected: 4.10-1. Fixed in: 4.11-1. Group: AVG-286. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — isc-dhcp31-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — isc-dhcp31-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: isc-dhcp-client — dhclient does not strip or escape shell meta-characters Related CVEs: CVE-2009-0692 CVE-2011-0997 Upstream summary: ISC reports: ISC dhclient did not strip or escape certain shell meta-characters in responses […]

Read more
FreeBSD 12 — telepathy-gabble — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — telepathy-gabble — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: telepathy-gabble — TLS verification bypass Related CVEs: CVE-2013-1431 Upstream summary: Simon McVittie reports: This release fixes a man-in-the-middle attack. If you use an unencrypted connection to a "legacy Jabber" (pre-XMPP) […]

Read more
FreeBSD 12 — p5-Dancer — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — p5-Dancer — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Dancer — possible to abuse session cookie values Upstream summary: Russell Jenkins reports: It was possible to abuse session cookie values so that file-based session stores such as Dancer::Session::YAML or […]

Read more
Amazon Linux 2 — bash — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — bash — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2020-1503 Related CVEs: CVE-2019-9924 Upstream summary: rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the […]

Read more
SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:018 (see also SUSE bugzilla) Related CVEs: CVE-2010-0405 CVE-2019-12900 CVE-2016-3189 Upstream summary: Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a […]

Read more
Alpine Linux edge — lame — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — lame — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 3.99.5-r6 📖 ~4 min read  •  Source: Alpine secdb entry — lame 3.99.5-r6 Related CVEs: CVE-2015-9099 CVE-2015-9100 CVE-2017-9410 CVE-2017-9411 CVE-2017-9412 CVE-2017-11720 Upstream summary: Alpine main repository for vedge ships lame 3.99.5-r6 which addresses CVE-2015-9099. Table of […]

Read more
FreeBSD 12 — mysql81-client — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mysql81-client — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL — Multiple vulnerabilities Upstream summary: Oracle reports: 36 new security patches for Oracle MySQL. 11 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over […]

Read more
FreeBSD 12 — inn — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — inn — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: inn — plaintext command injection into encrypted channel Related CVEs: CVE-2011-0411 CVE-2012-3523 Upstream summary: INN developers report: Fixed a possible plaintext command injection during the negotiation of a TLS layer. […]

Read more
FreeBSD 12 — charybdis — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — charybdis — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ircd-ratbox and charybdis — remote DoS vulnerability Upstream summary: atheme.org reports: All versions of Charybdis are vulnerable to a remotely-triggered crash bug caused by code originating from ircd-ratbox 2.0. (Incidentally, […]

Read more
CHAT