November 2024 - Page 28 of 94

Debian 12 — sketch — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — sketch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 November 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-2047 Upstream summary: The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated […]

Read more
NetBSD 9.4 — guile — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — guile — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2016-8605 Upstream summary: pkgsrc audit-packages flagged guile-[0-9]* for vulnerability class 'insecure-file-permissions'. Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-8605 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
Debian 12 — ceilometer — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ceilometer — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 November 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6384 CVE-2014-4615 CVE-2019-3830 Upstream summary: (1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string […]

Read more
Alpine Linux 3.20 — ldb — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux 3.20

Alpine Linux 3.20 — ldb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.20 / fixed in 1.3.5-r0 📖 ~4 min read  •  Source: Alpine secdb entry — ldb 1.3.5-r0 Related CVEs: CVE-2018-1140 Upstream summary: Alpine main repository for vv3.20 ships ldb 1.3.5-r0 which addresses CVE-2018-1140. Table of contents Symptom & Impact Environment […]

Read more
NetBSD 9.4 — ap13-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — ap13-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2009-0796 CVE-2007-1349 Upstream summary: pkgsrc audit-packages flagged ap13-perl<1.29nb2 for vulnerability class 'cross-site-scripting'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0796 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
Ubuntu 18.04 — libmodule-scandeps-perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libmodule-scandeps-perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 November 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7117-1 Related CVEs: CVE-2024-10224 CVE-2024-11003 CVE-2024-48990 CVE-2024-48991 CVE-2024-48992 Upstream summary: Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly […]

Read more
NetBSD 9.4 — zabbix-frontend — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — zabbix-frontend — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2024-36467 CVE-2023-32721 CVE-2024-22117 CVE-2024-22119 CVE-2024-36465 CVE-2024-36466 CVE-2024-36469 CVE-2024-42327  +9 more Upstream summary: pkgsrc audit-packages flagged zabbix-frontend<6.0.33 for vulnerability class 'privilege-escalation'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2024-36467 Table of contents Symptom & Impact Environment […]

Read more
Ubuntu 24.04 — provd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — provd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 November 2024 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6912-1 Related CVEs: CVE-2024-6714 https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 Upstream summary: James Henstridge discovered that provd incorrectly handled environment variables. A local attacker could possibly use this issue to run arbitrary programs and escalate […]

Read more
Ubuntu 20.04 — mpg123 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — mpg123 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 November 2024 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7092-2 Related CVEs: CVE-2024-10573 https://launchpad.net/bugs/2089680 Upstream summary: USN-7092-1 fixed a vulnerability in mpg123. Bastien Roucariès discovered that the fix was incomplete on Ubuntu 20.04 LTS. This update fixes the problem. […]

Read more
Alpine Linux 3.19 — e2fsprogs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.19

Alpine Linux 3.19 — e2fsprogs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.19 / fixed in 1.45.5-r0 📖 ~4 min read  •  Source: Alpine secdb entry — e2fsprogs 1.45.5-r0 Related CVEs: CVE-2019-5188 CVE-2019-5094 Upstream summary: Alpine main repository for vv3.19 ships e2fsprogs 1.45.5-r0 which addresses CVE-2019-5188. Table of contents Symptom & Impact […]

Read more
CHAT