March 2022 - Page 37 of 70

How to Set Up Tripwire for File Integrity Monitoring on RHEL 7 — step-by-step RHEL 7 tutorial on Progressive Robot

How to Set Up Tripwire for File Integrity Monitoring on RHEL 7

How to Set Up Tripwire for File Integrity Monitoring on RHEL 7 File Integrity Monitoring (FIM) is the practice of detecting unauthorised changes to critical system files, configuration files, and binaries. When an attacker compromises a system, they often modify files to install backdoors, alter logging behaviour, or escalate privileges. Tripwire creates a cryptographic baseline […]

Read more
Common Problems 120623

Debian 11: UFW blocks required application ports

🟡 Medium   ⏱ 5–30 min  Last verified: 16 March 2022 Affected versions: Debian 11 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
IBM AIX 7.3 — CVE-1999-0010 — denial of service — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-1999-0010 — denial of service — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 15 March 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-1999-0010, IBM PSIRT advisory page CVE: CVE-1999-0010 NVD summary: Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. References: ftp://patches.sgi.com/support/free/security/advi   www1.itrc.hp.com/service/cki/docDisplay.do?docId   ftp://patches.sgi.com/support/free/security/advi Table of contents Symptom […]

Read more
FreeBSD 13 — proxytunnel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — proxytunnel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: proxytunnel — format string vulnerability Related CVEs: CVE-2004-0992 Upstream summary: A Gentoo Linux Security Advisory reports: Florian Schilhabel of the Gentoo Linux Security Audit project found a format string vulnerability […]

Read more
FreeBSD 13 — opendmarc — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — opendmarc — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenDMARC – Remote denial of service Related CVEs: CVE-2019-16378 CVE-2019-20790 CVE-2020-12272 CVE-2020-12460 CVE-2021-34555 Upstream summary: OpenDMARC 1.4.1 and 1.4.1.1 will dereference a NULL pointer when encountering a multi-value From: header […]

Read more
FreeBSD 13 — ark — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ark — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ark — extraction outside of extraction directory Related CVEs: CVE-2020-16116 CVE-2020-24654 Upstream summary: Albert Astals Cid reports: Overview A maliciously crafted TAR archive containing symlink entries would install files anywhere […]

Read more
FreeBSD 13 — openslp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openslp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openslp — denial of service vulnerability Related CVEs: CVE-2015-5155 Upstream summary: Qinghao Tang reports: The function ParseExtension() in openslp 1.2.1 contains vulnerability: an attacker can cause a denial of service […]

Read more
FreeBSD 13 — postgresql90-server — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql90-server — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: End of Life Ports Related CVEs: CVE-2014-8161 CVE-2015-0241 CVE-2015-0242 CVE-2015-0243 CVE-2015-0244 CVE-2015-3165 CVE-2015-3166 CVE-2015-3167  +2 more Upstream summary: These packages have reached End of Life status and/or have been removed […]

Read more
FreeBSD 13 — helm — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — helm — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Helm — client unpacking chart that contains malicious content Upstream summary: Helm security notice A specially crafted chart may be able to unpack content into locations on the filesystem outside […]

Read more
FreeBSD 13 — php56-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php56-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 Upstream summary: The PHP project reports: Core: Fixed bug #69793 (Remotely triggerable stack exhaustion via recursive method calls). Fixed bug #70121 […]

Read more
CHAT