chris

FreeBSD 13 — apache22-event-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — apache22-event-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache22 — chunk header parsing defect Related CVEs: CVE-2012-0833 CVE-2012-2687 CVE-2012-3499 CVE-2012-4558 CVE-2013-1862 CVE-2013-1896 CVE-2013-5704 CVE-2013-6438  +5 more Upstream summary: Apache Foundation reports: CVE-2015-3183 core: Fix chunk header parsing defect. […]

Read more
Spring @Autowired Annotation — step-by-step DevOps tutorial on Progressive Robot

Spring @Autowired Annotation

URL: https://www.progressiverobot.com/spring-autowired-annotation/ Spring @Autowired annotation is used for automatic dependency injection. Spring framework is built on [dependency injection](/community/tutorials/spring-dependency-injection "Spring Dependency Injection Example with Annotations and XML Configuration") and we inject the class dependencies through spring bean configuration file. Spring @Autowired Annotation ![spring @autowired annotation, @Autowired, spring autowiring, spring @autowired](images/spring-autowired-annotation-section-1.png) Usually we provide bean configuration details […]

Read more
FreeBSD 12 — py38-numpy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-numpy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 June 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-numpy — Missing return-value validation of the function PyArray_DescrNew Related CVEs: CVE-2021-41495 Upstream summary: Numpy reports: At most call-sites for PyArray_DescrNew, there are no validations of its return, but an […]

Read more
log4j.properties File Example — step-by-step Programming tutorial on Progressive Robot

log4j.properties File Example

URL: https://www.progressiverobot.com/log4j-properties-file-example/ In [log4j tutorial](/community/tutorials/log4j-tutorial), we saw how to use log4j xml based configuration. But log4j.xml is verbose, so log4j framework provide option to read configuration from properties file too. Since properties file don't have any defined schema to validate, we have to be more careful with it. Today we will see how XML configurations […]

Read more
Ubuntu 20.04 — tigervnc — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — tigervnc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 June 2021 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5965-1 Related CVEs: CVE-2020-26117 Upstream summary: It was discovered that TigerVNC mishandled TLS certificate exceptions. An attacker could use this vulnerability to impersonate any server after a client had added […]

Read more
Oracle Linux 8 — virt:kvm_utils — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — virt:kvm_utils — vulnerability — patch and remediation guide (ELSA-2022-9172)

🟠 High   ⏱ 15–60 min  Last verified: 12 June 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9172 Related CVEs: CVE-2021-3593 CVE-2021-3713 CVE-2020-29130 CVE-2021-3594 CVE-2021-3595 CVE-2021-20257 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
CHAT