February 2025 - Page 9 of 91

Alpine Linux 3.19 — grafana — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.19

Alpine Linux 3.19 — grafana — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.19 / fixed in 9.1.2-r0 📖 ~4 min read  •  Source: Alpine secdb entry — grafana 9.1.2-r0 Related CVEs: CVE-2022-31176 CVE-2022-31097 CVE-2022-31107 CVE-2022-29170 CVE-2022-21702 CVE-2022-21703 CVE-2022-21713 CVE-2022-21673  +10 more Upstream summary: Alpine community repository for vv3.19 ships grafana 9.1.2-r0 which […]

Read more
Rocky Linux 8 — podman — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Rocky Linux 8

Rocky Linux 8 — podman — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Rocky Linux 8 📖 ~4 min read  •  Source: Rocky Linux RXSA RLSA-2026:4672 Related CVEs: CVE-2025-61726 CVE-2025-61728 CVE-2025-68121 CVE-2024-24785 CVE-2025-61729 CVE-2025-65637 CVE-2025-47913 CVE-2025-52881  +12 more Upstream summary: The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. […]

Read more
Amazon Linux 2 — golist — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — golist — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-3069 Related CVEs: CVE-2025-47912 CVE-2025-58183 CVE-2025-58185 CVE-2025-58186 CVE-2025-58187 CVE-2025-58188 CVE-2025-58189 CVE-2025-61723  +12 more Upstream summary: net/url: insufficient validation of bracketed IPv6 hostnames The Parse function permitted values other than IPv6 […]

Read more
FreeBSD 14 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer1-plugins-ogg — Out-of-bounds write in Ogg demuxer Related CVEs: CVE-2024-47615 Upstream summary: The GStreamer Security Center reports: An out-of-bounds write in the Ogg demuxer that can cause crashes for certain […]

Read more
FreeBSD 13 — sudo-rs-coexist — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sudo-rs-coexist — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sudo-rs — Authenticating user not recorded properly in timestamp Related CVEs: CVE-2025-64170 CVE-2025-64517 Upstream summary: Trifecta Tech Foundation reports: With Defaults targetpw (or Defaults rootpw) enabled, the password of the […]

Read more
FreeBSD 14 — msmtp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — msmtp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: msmtp — certificate-verification issue Related CVEs: CVE-2019-8337 Upstream summary: msmtp developers report: In msmtp 1.8.2, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. Table of contents […]

Read more
FreeBSD 14 — ru-apache+mod_ssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ru-apache+mod_ssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache 1.3 — mod_proxy reverse proxy exposure Related CVEs: CVE-2003-0993 CVE-2004-0700 CVE-2004-0885 CVE-2004-0940 CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 CVE-2011-3368 Upstream summary: Apache HTTP server project reports: An exposure was found when using […]

Read more
Debian 12 — node-lodash — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-lodash — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-16487 CVE-2018-3721 CVE-2019-1010266 CVE-2019-10744 CVE-2020-28500 CVE-2020-8203 CVE-2021-23337 CVE-2025-13465  +2 more Upstream summary: A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep […]

Read more
Ubuntu 22.04 — puma — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — puma — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7031-2 Related CVEs: CVE-2024-45614 CVE-2020-11076 CVE-2020-11077 CVE-2022-23634 CVE-2022-24790 CVE-2023-40175 CVE-2024-21647 Upstream summary: USN-7031-1 fixed CVE-2024-45614 in Puma for Ubuntu 24.04 LTS. This update fixes the CVE for Ubuntu 22.04 LTS […]

Read more
Ubuntu 20.04 — php-twig — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — php-twig — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7456-1 Related CVEs: CVE-2024-45411 CVE-2024-51754 CVE-2019-9942 CVE-2022-23614 CVE-2022-39261 Upstream summary: Fabien Potencier discovered that Twig did not run sandbox security checks in some circumstances. An attacker could possibly use this […]

Read more
CHAT