2025 - Page 1157 of 1252

NetBSD 10.0 — php-dotclear — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — php-dotclear — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2023-53952 Upstream summary: pkgsrc audit-packages flagged php{56,74,81,82,83,84}-dotclear-[0-9]* for vulnerability class 'arbitrary-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-53952 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
NetBSD 10.0 — heimdal — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — heimdal — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2011-4862 CVE-2022-44640 CVE-2017-11103 CVE-2017-6594 CVE-2017-17439 CVE-2018-16860 CVE-2019-12098 CVE-2022-45142  +5 more Upstream summary: pkgsrc audit-packages flagged heimdal<0.6.1 for vulnerability class 'remote-trust'. Reference: http://www.pdc.kth.se/heimdal/advisory/2004-04-01/ Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 14 — php72-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php72-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
NetBSD 10.0 — enlightenment — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — enlightenment — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2014-1845 CVE-2014-1846 Upstream summary: pkgsrc audit-packages flagged enlightenment<0.17.6 for vulnerability class 'privilege-escalation'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2014-1845 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 14 — apache22-event-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — apache22-event-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache22 — chunk header parsing defect Related CVEs: CVE-2012-0833 CVE-2012-2687 CVE-2012-3499 CVE-2012-4558 CVE-2013-1862 CVE-2013-1896 CVE-2013-5704 CVE-2013-6438  +5 more Upstream summary: Apache Foundation reports: CVE-2015-3183 core: Fix chunk header parsing defect. […]

Read more
FreeBSD 14 — a2ps-letterdj — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — a2ps-letterdj — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: a2ps — insecure temporary file creation Related CVEs: CVE-2004-1170 CVE-2004-1377 Upstream summary: A Secunia Security Advisory reports that Javier Fernández-Sanguino Peña has found temporary file creation vulnerabilities in the fixps […]

Read more
AlmaLinux 8 — libreswan — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — libreswan — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2023:3107 Related CVEs: CVE-2023-2295 CVE-2023-30570 CVE-2022-23094 CVE-2024-3652 CVE-2024-2357 CVE-2023-38710 CVE-2023-38711 CVE-2023-38712  +1 more Upstream summary: Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and […]

Read more
Ubuntu 18.04 — freetype — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — freetype — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 January 2025 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7352-2 Related CVEs: CVE-2022-27406 CVE-2025-27363 CVE-2022-27404 CVE-2022-27405 CVE-2022-31782 CVE-2020-15999 Upstream summary: USN-7352-1 fixed a vulnerability in FreeType. This update provides the corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 […]

Read more
openSUSE Tumbleweed — python310-Jinja2 — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python310-Jinja2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9150 (see also SUSE bugzilla) Related CVEs: CVE-2024-34064 Upstream summary: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot […]

Read more
CHAT