chris

FreeBSD 12 — php5-phar — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php5-phar — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-5589 CVE-2015-5590 CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 CVE-2015-7803 CVE-2015-7804 Upstream summary: PHP reports: Phar: Fixed bug #69720 (Null pointer dereference in phar_get_fp_offset()). Fixed bug #70433 (Uninitialized […]

Read more
FreeBSD 12 — groovy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — groovy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: groovy — remote execution of untrusted code/DoS vulnerability Related CVEs: CVE-2015-3253 CVE-2016-6814 Upstream summary: The Apache Groovy project reports: When an application with Groovy on classpath uses standard Java serialization […]

Read more
Alpine Linux edge — libxdmcp — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — libxdmcp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 1.1.2-r3 📖 ~4 min read  •  Source: Alpine secdb entry — libxdmcp 1.1.2-r3 Related CVEs: CVE-2017-2625 Upstream summary: Alpine main repository for vedge ships libxdmcp 1.1.2-r3 which addresses CVE-2017-2625. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — typespeed — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — typespeed — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typespeed — arbitrary code execution Related CVEs: CVE-2005-0105 Upstream summary: Debian reports: Ulf Härnhammar from the Debian Security Audit Project discovered a problem in typespeed, a touch-typist trainer disguised as […]

Read more
FreeBSD 12 — xorg-dmx — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xorg-dmx — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xorg-server — Multiple input validation failures in X server XKB extension Related CVEs: CVE-2017-12176 CVE-2017-12177 CVE-2017-12178 CVE-2017-12179 CVE-2017-12180 CVE-2017-12181 CVE-2017-12182 CVE-2017-12183  +12 more Upstream summary: The X.org project reports: These […]

Read more
Ubuntu 16.04 — xcftools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — xcftools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 March 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5988-1 Related CVEs: CVE-2019-5086 CVE-2019-5087 Upstream summary: It was discovered that integer overflows vulnerabilities existed in Xcftools. An attacker could use this to cause a denial of service (system crash) […]

Read more
Ubuntu 18.04 — libtirpc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libtirpc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3759-1 Related CVEs: CVE-2016-4429 CVE-2017-8779 CVE-2018-14622 Upstream summary: Aldy Hernandez discovered that libtirpc incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. […]

Read more
Gentoo Linux — media-libs/libaacplus — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Gentoo Linux

Gentoo Linux — media-libs/libaacplus — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Gentoo Linux 📖 ~4 min read  •  Source: Gentoo GLSA GLSA-202209-13 Related CVEs: CVE-2017-7603 CVE-2017-7604 CVE-2017-7605 Upstream summary: Multiple vulnerabilities have been discovered in libaacplus. Please review the CVE identifiers referenced below for details. Table of contents Symptom & Impact Environment & […]

Read more
Ubuntu 14.04 — libseccomp — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libseccomp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 March 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4001-2 Related CVEs: CVE-2019-9893 Upstream summary: USN-4001-1 fixed a vulnerability in libseccomp. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Jann Horn discovered that libseccomp […]

Read more
Alpine Linux edge — perl-email-address — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — perl-email-address — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 1.912-r0 📖 ~4 min read  •  Source: Alpine secdb entry — perl-email-address 1.912-r0 Related CVEs: CVE-2018-12558 Upstream summary: Alpine main repository for vedge ships perl-email-address 1.912-r0 which addresses CVE-2018-12558. Table of contents Symptom & Impact Environment […]

Read more
CHAT