March 2022 - Page 45 of 70

Debian 11 — lmbench — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lmbench — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4968 Upstream summary: The (1) rccs and (2) STUFF scripts in lmbench 3.0-a7 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/sdiff.##### temporary […]

Read more
Debian 11 — kile — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kile — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-6085 Upstream summary: Kile before 1.9.3 does not assign a backup file the same permissions as the original file, which might allow local users to obtain sensitive information. […]

Read more
AlmaLinux 8 — ctags — vulnerability — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — ctags — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2023:2863 Related CVEs: CVE-2022-4515 Upstream summary: Ctags is a C programming language indexing and cross-reference tool. Security Fix(es): * ctags: arbitrary command execution via a tag file with a crafted filename (CVE-2022-4515) […]

Read more
Debian 11 — scapy — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — scapy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-1010142 Upstream summary: scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector […]

Read more
How to Configure rkhunter Rootkit Scanner on Debian 9 — step-by-step Debian 9 tutorial on Progressive Robot

How to Configure rkhunter Rootkit Scanner on Debian 9

Introduction This guide explains how to Configure rkhunter Rootkit Scanner on Debian 9 on Debian 9 Stretch. Debian Stretch uses systemd for service management, nftables as the underlying packet filter (with ufw or iptables front-ends still available), and AppArmor for mandatory access control. Every command is designed for a minimal Debian 9 install with the […]

Read more
Debian 11 — chkrootkit — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — chkrootkit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-0476 Upstream summary: The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse […]

Read more
Alpine Linux edge — librewolf — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — librewolf — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 99.0-r0 📖 ~4 min read  •  Source: Alpine secdb entry — librewolf 99.0-r0 Related CVEs: CVE-2022-1097 CVE-2022-24713 CVE-2022-28281 CVE-2022-28282 CVE-2022-28283 CVE-2022-28284 CVE-2022-28285 CVE-2022-28286  +12 more Upstream summary: Alpine community repository for vedge ships librewolf 99.0-r0 which […]

Read more
Debian 11 — schroot — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — schroot — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-2787 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 18.04 — grub2-signed — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — grub2-signed — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 March 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4992-1 Related CVEs: CVE-2020-14372 CVE-2020-25632 CVE-2020-27749 CVE-2020-27779 CVE-2021-20225 CVE-2021-20233 https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass2021 https://launchpad.net/bugs/1889556  +9 more Upstream summary: Máté Kukri discovered that the acpi command in GRUB 2 allowed privileged users to load […]

Read more
FreeBSD 12 — mysql-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mysql-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 March 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL — Multiple vulnerabilities Related CVEs: CVE-2004-0381 CVE-2004-0836 CVE-2018-25032 CVE-2022-1292 CVE-2022-1941 CVE-2022-2097 CVE-2022-21455 CVE-2022-21509  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 24 new security patches for […]

Read more
CHAT