chris

openSUSE Tumbleweed — python36-rpyc — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-rpyc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2020:0685-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-16328 Upstream summary: In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code […]

Read more
Debian 9 — samba — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — samba — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 May 2019 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-11103 CVE-2017-12150 CVE-2017-14746 CVE-2018-1050 CVE-2018-10858 CVE-2018-14629 CVE-2018-16860 CVE-2019-3880 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix […]

Read more
FreeBSD 12 — davmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — davmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: davmail — fix potential CVE-2014-3566 vulnerability (POODLE) Related CVEs: CVE-2014-3566 Upstream summary: Mickaël Guessant reports: DavMail 4.6.0 released Enhancements: Fix potential CVE-2014-3566 vulnerability. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — ilohamail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ilohamail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: "Content-Type" XSS vulnerability affecting other webmail systems Related CVEs: CVE-2004-0519 Upstream summary: Roman Medina-Heigl Hernandez did a survey which other webmail systems where vulnerable to a bug he discovered in […]

Read more
openSUSE Tumbleweed — python38-numpy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python38-numpy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2017:3010-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-12852 CVE-2019-6446 Upstream summary: The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into […]

Read more
FreeBSD 12 — py311-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py311-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
FreeBSD 12 — logstash — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — logstash — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: logstash — password disclosure vulnerability Related CVEs: CVE-2014-3120 CVE-2014-4326 CVE-2015-4152 CVE-2015-5378 Upstream summary: Logstash developers report: Passwords Printed in Log Files under Some Conditions It was discovered that, in Logstash […]

Read more
Ubuntu 16.04 — hdf5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — hdf5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5272-1 Related CVEs: CVE-2018-17233 CVE-2018-17234 CVE-2018-17237 CVE-2017-17505 CVE-2017-17506 CVE-2017-17508 Upstream summary: It was discovered that HDF5 incorrectly handled certain inputs. An attacker could possibly use this issue to cause a […]

Read more
Alpine Linux edge — pcmanfm — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — pcmanfm — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 1.2.5-r1 📖 ~4 min read  •  Source: Alpine secdb entry — pcmanfm 1.2.5-r1 Related CVEs: CVE-2017-8934 Upstream summary: Alpine community repository for vedge ships pcmanfm 1.2.5-r1 which addresses CVE-2017-8934. Table of contents Symptom & Impact Environment […]

Read more
SLES 15 — go1.12 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.12 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2940-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-17596 CVE-2019-16276 Upstream summary: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public […]

Read more
CHAT