2022 - Page 615 of 828

How to Use Podman on FreeBSD 12 — step-by-step FreeBSD 12 tutorial on Progressive Robot

How to Use Podman on FreeBSD 12

Introduction Deploying use podman on freebsd 12 on a FreeBSD 12 machine differs from Linux in several important ways: packages come from the FreeBSD Ports Collection or the binary pkg repository, services are registered in /etc/rc.conf via sysrc(8), and firewall rules are written in pf.conf(5) syntax. This tutorial stays entirely within the standard base + […]

Read more
Debian 11 — cryptsetup — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — cryptsetup — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 April 2022 Affected versions: Debian 11 (bullseye) đź“– ~4 min read  â€˘  Source: Debian Security Tracker Related CVEs: CVE-2016-4484 CVE-2020-14382 CVE-2021-4122 Upstream summary: The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in […]

Read more
Debian 11 — radvd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — radvd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 April 2022 Affected versions: Debian 11 (bullseye) đź“– ~4 min read  â€˘  Source: Debian Security Tracker Related CVEs: CVE-2011-3601 CVE-2011-3602 CVE-2011-3604 CVE-2011-3605 Upstream summary: Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to execute arbitrary code or […]

Read more
Ubuntu 20.04 — libzstd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libzstd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 April 2022 Affected versions: Ubuntu 20.04 (focal) đź“– ~4 min read  â€˘  Source: Ubuntu Security Notice USN-4760-1 Related CVEs: CVE-2021-24031 CVE-2021-24032 Upstream summary: It was discovered that libzstd incorrectly handled file permissions. A local attacker could possibly use this issue to access certain files, contrary to […]

Read more
Ubuntu 18.04 — exempi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — exempi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

đźź  High   ⏱ 15–60 min  Last verified: 6 April 2022 Affected versions: Ubuntu 18.04 (bionic) đź“– ~4 min read  â€˘  Source: Ubuntu Security Notice USN-5483-1 Related CVEs: CVE-2018-12648 CVE-2021-36045 CVE-2021-36046 CVE-2021-36047 CVE-2021-36048 CVE-2021-36050 CVE-2021-36051 CVE-2021-36052  +12 more Upstream summary: It was discovered that Exempi incorrectly handled certain media files. If a user or automated […]

Read more
How to Set Up WireGuard VPN on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Set Up WireGuard VPN on Debian 11

Introduction This guide explains how to Set Up WireGuard VPN on Debian 11 on Debian 11 Bullseye. Debian Bullseye uses systemd for service management, nftables as the underlying packet filter (with ufw or iptables front-ends still available), and AppArmor for mandatory access control. Every command is designed for a minimal Debian 11 install with the […]

Read more
SLES 15 — kpartx — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kpartx — multiple vulnerabilities (2 CVEs) — patch and remediation guide

đźź  High   ⏱ 15–60 min  Last verified: 6 April 2022 Affected versions: SLES 15 đź“– ~4 min read  â€˘  Source: SUSE advisory SUSE-SU-2022:3707-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-41973 CVE-2022-41974 Upstream summary: multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users […]

Read more
SLES 15 — python2-numpy — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-numpy — multiple vulnerabilities (5 CVEs) — patch and remediation guide

đźź  High   ⏱ 15–60 min  Last verified: 6 April 2022 Affected versions: SLES 15 đź“– ~4 min read  â€˘  Source: SUSE advisory SUSE-CU-2022:314-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33430 CVE-2021-41495 CVE-2021-41496 CVE-2017-12852 CVE-2019-6446 Upstream summary: A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifying arrays of […]

Read more
openSUSE Tumbleweed — php-composer — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — php-composer — multiple vulnerabilities (3 CVEs) — patch and remediation guide

đźź  High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed đź“– ~4 min read  â€˘  Source: SUSE advisory openSUSE-SU-2022:0132-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24828 CVE-2021-41116 CVE-2021-29472 Upstream summary: Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a […]

Read more
Oracle Linux 8 — bind9.16 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — bind9.16 — vulnerability — patch and remediation guide (ELSA-2022-7643)

đźź  High   ⏱ 15–60 min  Last verified: 6 April 2022 Affected versions: Oracle Linux 8 đź“– ~4 min read  â€˘  Source: ELSA advisory ELSA-2022-7643 Related CVEs: CVE-2021-25220 CVE-2022-0396 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
CHAT