August 2024 - Page 41 of 99

Ubuntu 18.04 — cyrus-imapd — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — cyrus-imapd — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7224-1 Related CVEs: CVE-2019-18928 CVE-2021-33582 CVE-2024-34055 CVE-2019-11356 CVE-2019-19783 Upstream summary: It was discovered that non-authentication-related HTTP requests could be interpreted in an authentication context by a Cyrus IMAP Server when […]

Read more
Ubuntu 24.04 — keystone — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — keystone — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 August 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7857-1 Related CVEs: https://launchpad.net/bugs/2130629 Upstream summary: Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access […]

Read more
Alpine Linux 3.20 — ruby-activesupport — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.20

Alpine Linux 3.20 — ruby-activesupport — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.20 / fixed in 7.0.4.3-r0 📖 ~4 min read  •  Source: Alpine secdb entry — ruby-activesupport 7.0.4.3-r0 Related CVEs: CVE-2023-28120 CVE-2023-22796 Upstream summary: Alpine community repository for vv3.20 ships ruby-activesupport 7.0.4.3-r0 which addresses CVE-2023-28120. Table of contents Symptom & Impact […]

Read more
NetBSD 9.4 — kdelibs-2.2.1* — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — kdelibs — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Upstream summary: pkgsrc audit-packages flagged kdelibs for vulnerability class 'weak-ssl-authentication'. Reference: http://online.securityfocus.com/archive/1/286290/2002-08-08/2002-08-14/2 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
SLES 15 — python311-tornado6 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-tornado6 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10590 (see also SUSE bugzilla) Related CVEs: CVE-2024-52804 Upstream summary: Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to […]

Read more
FreeBSD 14 — linux-c6-flashplugin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-c6-flashplugin — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 August 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: flash — multiple vulnerabilities Related CVEs: CVE-2014-0547 CVE-2014-0548 CVE-2014-0549 CVE-2014-0550 CVE-2014-0551 CVE-2014-0552 CVE-2014-0553 CVE-2014-0554  +12 more Upstream summary: Adobe reports: These updates resolve type confusion vulnerabilities that could lead to […]

Read more
Alpine Linux 3.20 — cmark — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux 3.20

Alpine Linux 3.20 — cmark — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.20 / fixed in 0.30.3-r0 📖 ~4 min read  •  Source: Alpine secdb entry — cmark 0.30.3-r0 Related CVEs: CVE-2023-22486 Upstream summary: Alpine community repository for vv3.20 ships cmark 0.30.3-r0 which addresses CVE-2023-22486. Table of contents Symptom & Impact Environment […]

Read more
NetBSD 9.4 — apache — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — apache — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2006-3747 CVE-2009-1191 CVE-2010-0010 CVE-2011-3368 CVE-2011-3639 CVE-2011-4317 CVE-2012-0031 CVE-2012-0883  +12 more Upstream summary: pkgsrc audit-packages flagged apache<1.3.14 for vulnerability class 'remote-user-access'. Reference: http://httpd.apache.org/dist/httpd/CHANGES_1.3 Table of contents Symptom & Impact Environment […]

Read more
Debian 12 — perl — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — perl — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-0703 CVE-2002-1323 CVE-2003-0615 CVE-2003-0618 CVE-2003-0900 CVE-2004-0452 CVE-2004-0976 CVE-2005-0155  +12 more Upstream summary: An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for […]

Read more
FreeBSD 14 — apache+mod_ssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — apache+mod_ssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 August 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache 1.3 — mod_proxy reverse proxy exposure Related CVEs: CVE-2003-0993 CVE-2004-0700 CVE-2004-0885 CVE-2004-0940 CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 CVE-2011-3368 Upstream summary: Apache HTTP server project reports: An exposure was found when using […]

Read more
CHAT