chris

Arch Linux — smb4k — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — smb4k — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201705-11 Related CVEs: CVE-2017-8849 Upstream summary: Type: privilege escalation. Status: Fixed. Affected: 2.0.0-1. Fixed in: 2.0.0-2. Group: AVG-268. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
FreeBSD 12 — zabbix — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zabbix — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zabbix — php frontend multiple vulnerabilities Upstream summary: Secunia reports: Some vulnerabilities have been reported in the ZABBIX PHP frontend, which can be exploited by malicious people to conduct cross-site […]

Read more
FreeBSD 12 — jftpgw — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — jftpgw — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Arbitrary code execution via a format string vulnerability in jftpgw Related CVEs: CVE-2004-0448 Upstream summary: The log functions in jftpgw may allow remotely authenticated user to execute arbitrary code via […]

Read more
FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nss — Use-after-free in TLS 1.2 generating handshake hashes Related CVEs: CVE-2016-2834 CVE-2017-5461 CVE-2017-5462 CVE-2017-7805 Upstream summary: Mozilla reports: During TLS 1.2 exchanges, handshake hashes are generated which point to […]

Read more
FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: AccountsService — Insufficient path check in user_change_icon_file_authorized_cb() Related CVEs: CVE-2018-14036 Upstream summary: NVD reports: Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check […]

Read more
IBM AIX 7.2 — CVE-2018-20733 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2018-20733 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 16 February 2019 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2018-20733, IBM PSIRT advisory page CVE: CVE-2018-20733 NVD summary: BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. References: support.sas.com/kb/62/987.html   support.sas.com/kb/62/987.html Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — libxfce4gui — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libxfce4gui — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xfce — multiple vulnerabilities Related CVEs: CVE-2007-6531 CVE-2007-6532 Upstream summary: Gentoo reports: A remote attacker could entice a user to install a specially crafted "rc" file to execute arbitrary code […]

Read more
FreeBSD 12 — py27-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/py-ecdsa — multiple issues Related CVEs: CVE-2019-14853 CVE-2019-14859 Upstream summary: py-ecdsa developers report: Fix CVE-2019-14853 – possible DoS caused by malformed signature decoding. Fix CVE-2019-14859 – signature malleability caused by […]

Read more
openSUSE Tumbleweed — python36-colander — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-colander — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-18361 Upstream summary: In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of […]

Read more
openSUSE Tumbleweed — nagios — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — nagios — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2006:011 (see also SUSE bugzilla) Related CVEs: CVE-2006-2162 CVE-2007-5803 CVE-2008-4796 CVE-2011-1523 CVE-2013-2214 CVE-2013-4214 CVE-2014-1878 CVE-2016-0726  +8 more Upstream summary: Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before […]

Read more
CHAT