2022 - Page 538 of 828

FreeBSD 13 — nbsmtp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nbsmtp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nbsmtp — format string vulnerability Upstream summary: When nbsmtp is executed in debug mode, server messages will be printed to stdout and logged via syslog. Syslog is used insecurely and […]

Read more
How to Configure Mandatory Access Control on FreeBSD 12 — step-by-step FreeBSD 12 tutorial on Progressive Robot

How to Configure Mandatory Access Control on FreeBSD 12

Introduction How to Configure Mandatory Access Control on FreeBSD 12 is a core administration task for any FreeBSD 12 server operator. FreeBSD 12 ships with the 15.0-RELEASE kernel, ZFS as the default root filesystem, Capsicum capability sandboxing improvements, and an updated ports tree. Unlike Linux distributions, FreeBSD uses rc(8) for service management, pf for packet […]

Read more
FreeBSD 13 — punbb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — punbb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: punbb — NULL byte injection vulnerability Related CVEs: CVE-2006-4759 Upstream summary: CVE Mitre reports: PunBB 1.2.12 does not properly handle an avatar directory pathname ending in %00, which allows remote […]

Read more
Amazon Linux 2 — go-rpm-macros — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — go-rpm-macros — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2022-1863 Related CVEs: CVE-2022-1705 CVE-2022-1962 CVE-2022-1996 CVE-2022-24675 CVE-2022-27191 CVE-2022-27664 CVE-2022-28131 CVE-2022-28327  +8 more Upstream summary: 2023-05-11: CVE-2022-1996 has changed status to NOT AFFECTED for this package and has been removed […]

Read more
Ubuntu 20.04 — apache-log4j2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — apache-log4j2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 May 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5222-1 Related CVEs: CVE-2021-44832 CVE-2021-45105 CVE-2021-45046 CVE-2021-44228 Upstream summary: It was discovered that Apache Log4j 2 was vulnerable to remote code execution (RCE) attack when configured to use a JDBC […]

Read more
Ubuntu 22.04 — networkd-dispatcher — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — networkd-dispatcher — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 May 2022 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5395-2 Related CVEs: https://launchpad.net/bugs/1971550 CVE-2022-29799 CVE-2022-29800 Upstream summary: USN-5395-1 fixed vulnerabilities in networkd-dispatcher. Unfortunately that update was incomplete and could introduce a regression. This update fixes the problem. We apologize […]

Read more
Ubuntu 20.04 — libpano13 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libpano13 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6163-1 Related CVEs: CVE-2021-20307 CVE-2021-33293 Upstream summary: It was discovered that pano13 did not properly validate the prefix provided for PTcrop's output. An attacker could use this issue to cause […]

Read more
Oracle Linux 8 — libxml2 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — libxml2 — vulnerability — patch and remediation guide (ELSA-2023-0173)

🟡 Medium   ⏱ 10–30 min  Last verified: 10 May 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-0173 Related CVEs: CVE-2022-40303 CVE-2022-40304 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
How to Configure the System Timezone on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Configure the System Timezone on Debian 11

Introduction Deploying configure the system timezone on debian 11 on a Debian 11 Bullseye machine is straightforward thanks to Debian’s policy-compliant packaging. Unlike rpm-based distributions, Debian stores configuration helpers in /etc/default/, uses update-rc.d for older init scripts, and provides dpkg-reconfigure for interactive package configuration. This tutorial stays on the systemd path throughout. Prerequisites You will […]

Read more
Arch Linux — polkit — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — polkit — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-202204-2 Related CVEs: CVE-2021-4115 CVE-2021-4034 CVE-2018-19788 CVE-2021-3560 Upstream summary: Type: multiple issues. Status: Fixed. Affected: 0.120-3. Fixed in: 0.120-5. Group: AVG-2654. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
CHAT