February 2024 - Page 23 of 91

Debian 12 — php-horde-crypt — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — php-horde-crypt — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-7413 CVE-2017-7414 Upstream summary: In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated […]

Read more
NetBSD 9.4 — cargo-nextest — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — cargo-nextest — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Upstream summary: pkgsrc audit-packages flagged cargo-nextest<0.9.135 for vulnerability class 'unknown'. Reference: https://github.com/rust-openssl/rust-openssl/releases/tag/openssl-v0.10.78 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
FreeBSD 14 — tor — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — tor — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/tor — SOCKS4(a) inversion bug Related CVEs: CVE-2005-2643 CVE-2006-0414 CVE-2009-0414 CVE-2009-0936 CVE-2009-0937 CVE-2009-0938 CVE-2010-1676 CVE-2011-0427  +3 more Upstream summary: The Tor Project reports: TROVE-2022-002: The SafeSocks option for SOCKS4(a) is […]

Read more
openSUSE Tumbleweed — uriparser — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — uriparser — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:0165-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19198 CVE-2018-19199 CVE-2018-20721 CVE-2024-34402 CVE-2024-34403 CVE-2018-19200 CVE-2021-46141 CVE-2021-46142 Upstream summary: An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a […]

Read more
FreeBSD 14 — php56-mbstring — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php56-mbstring — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: oniguruma — multiple vulnerabilities Related CVEs: CVE-2015-8874 CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772  +5 more Upstream summary: the PHP project reports: A stack out-of-bounds read occurs in match_at() during […]

Read more
Windows Server 2019 — KB5035853 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2019

Windows Server 2019 — KB5035853 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2019 📖 ~4 min read  •  Source: Microsoft KB5035853 • MSRC update-guide entry Related CVEs: CVE-2024-21407 CVE-2024-21408 CVE-2024-21429 CVE-2024-21430 CVE-2024-21438 CVE-2024-21439 CVE-2024-21441 CVE-2024-21443  +12 more Affected components: Windows Server 2019 (Server Core installation) Table of contents Symptom & Impact Environment […]

Read more
Debian 12 — fastdds — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — fastdds — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-38425 CVE-2023-24010 CVE-2023-39534 CVE-2023-39945 CVE-2023-39946 CVE-2023-39947 CVE-2023-39948 CVE-2023-39949  +12 more Upstream summary: eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends […]

Read more
NetBSD 9.4 — python39 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — python39 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2022-42919 CVE-2023-6597 CVE-2020-27619 CVE-2021-3177 CVE-2021-23336 CVE-2021-29921 CVE-2022-0391 CVE-2021-3737  +12 more Upstream summary: pkgsrc audit-packages flagged python39<3.9.16 for vulnerability class 'arbitrary-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-42919 Table of contents Symptom & Impact Environment […]

Read more
Debian 12 — slirp4netns — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — slirp4netns — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-14378 CVE-2019-15890 CVE-2019-6778 CVE-2019-9824 CVE-2020-10756 CVE-2020-1983 CVE-2020-8608 Upstream summary: ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a […]

Read more
Debian 12 — node-stringstream — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-stringstream — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 February 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-21270 Upstream summary: Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is […]

Read more
CHAT