chris

Ubuntu 18.04 — libarchive-zip-perl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libarchive-zip-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3703-1 Related CVEs: CVE-2018-10860 Upstream summary: It was discovered that the Archive Zip module incorrectly handled certain inputs. An attacker could possibly use this to access sensitive information. Table of […]

Read more
Debian 9 — augeas — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — augeas — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-7555 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — conky — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — conky — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2011-3616 Upstream summary: The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf. Table […]

Read more
Debian 9 — plexus-archiver — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — plexus-archiver — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-1002200 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 16.04 — transmission — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — transmission — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 August 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3533-1 Related CVEs: CVE-2018-5702 Upstream summary: It was discovered that Transmission incorrectly handled certain POST requests to the RPC server and allowed DNS rebinding attack. An attacker could possibly use […]

Read more
Amazon Linux 2 — libgovirt — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — libgovirt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2220 Related CVEs: CVE-2018-10893 Upstream summary: Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to […]

Read more
SLES 15 — libfreetype6 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libfreetype6 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 August 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:721-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-8287 CVE-2009-0946 CVE-2010-2497 CVE-2010-2805 CVE-2010-3053 CVE-2010-3054 CVE-2010-3311 CVE-2010-3814  +12 more Upstream summary: FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer […]

Read more
Ubuntu 18.04 — lxc — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — lxc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 August 2018 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3730-1 Related CVEs: CVE-2018-6556 Upstream summary: Matthias Gerstner discovered that LXC incorrectly handled the lxc-user-nic utility. A local attacker could possibly use this issue to open arbitrary files. Table of […]

Read more
Debian 9 — mariadb-10.1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — mariadb-10.1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 August 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-10268 CVE-2017-3636 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
CHAT