August 2024 - Page 24 of 99

NetBSD 9.4 — ruby-actionpack51 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — ruby-actionpack51 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2019-5418 CVE-2020-8164 CVE-2020-8162 CVE-2019-5419 Upstream summary: pkgsrc audit-packages flagged ruby{22,23,24,25,26}-actionpack51<5.1.6.2 for vulnerability class 'arbitrary-file-reading'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2019-5418 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
FreeBSD 14 — racoon — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — racoon — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 August 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: racoon — remote denial-of-service Related CVEs: CVE-2004-0155 CVE-2004-0164 CVE-2004-0183 CVE-2004-0184 CVE-2004-0392 CVE-2004-0403 CVE-2005-0398 Upstream summary: Sebastian Krahmer discovered that the racoon ISAKMP daemon could be crashed with a maliciously crafted […]

Read more
Amazon Linux 2023 — dnsmasq — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — dnsmasq — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1516 Related CVEs: CVE-2023-50387 CVE-2023-50868 CVE-2023-28450 CVE-2022-0934 Upstream summary: No CVE associated with this advisory Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
Amazon Linux 2 — unixODBC — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — unixODBC — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2565 Related CVEs: CVE-2024-1013 CVE-2018-7409 CVE-2018-7485 Upstream summary: An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 […]

Read more
Debian 12 — minizinc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — minizinc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-46046 Upstream summary: An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is […]

Read more
AlmaLinux 8 — python-docutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — python-docutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2024:10953 Related CVEs: CVE-2024-53899 CVE-2023-40217 CVE-2023-24329 CVE-2019-7164 CVE-2019-7548 CVE-2019-9636 CVE-2022-40897 CVE-2022-48560  +12 more Upstream summary: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic […]

Read more
Debian 12 — gst-plugins-base1.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gst-plugins-base1.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-9811 CVE-2017-5837 CVE-2017-5839 CVE-2017-5842 CVE-2017-5844 CVE-2019-9928 CVE-2021-3522 CVE-2023-37328  +12 more Upstream summary: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows […]

Read more
Windows Server 2022 — KB5034119 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2022

Windows Server 2022 — KB5034119 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2022 📖 ~4 min read  •  Source: Microsoft KB5034119 • MSRC update-guide entry Related CVEs: CVE-2024-20674 CVE-2024-29059 CVE-2024-20654 CVE-2024-20657 CVE-2024-20658 CVE-2024-20680 CVE-2024-20682 CVE-2024-20683  +12 more Affected components: Windows Server 2022 Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, […]

Read more
Alpine Linux 3.20 — njs — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.20

Alpine Linux 3.20 — njs — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.20 / fixed in 0.7.3-r0 📖 ~4 min read  •  Source: Alpine secdb entry — njs 0.7.3-r0 Related CVEs: CVE-2021-46462 CVE-2021-46463 CVE-2022-25139 CVE-2021-46461 Upstream summary: Alpine community repository for vv3.20 ships njs 0.7.3-r0 which addresses CVE-2021-46462. Table of contents Symptom […]

Read more
Debian 12 — exempi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — exempi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-18233 CVE-2017-18234 CVE-2017-18235 CVE-2017-18236 CVE-2017-18237 CVE-2017-18238 CVE-2018-12648 CVE-2018-7728  +12 more Upstream summary: An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp […]

Read more
CHAT