IT, Cloud & DevOps Blog

FreeBSD 12 — py35-diffoscope — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py35-diffoscope — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: diffoscope — arbitrary file write Related CVEs: CVE-2017-0359 Upstream summary: Ximin Luo reports: [v67] introduced a security hole where diffoscope may write to arbitrary locations on disk depending on the […]

Read more
FreeBSD 12 — py35-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py35-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: buildbot — OAuth Authentication Vulnerability Related CVEs: CVE-2019-12300 CVE-2019-7313 Upstream summary: Buildbot accepted user-submitted authorization token from OAuth and used it to authenticate user. The vulnerability can lead to malicious […]

Read more
FreeBSD 12 — linux-f10-png — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-f10-png — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: png — memory corruption/possible remote code execution Related CVEs: CVE-2011-3048 Upstream summary: The PNG project reports: libpng fails to correctly handle malloc() failures for text chunks (in png_set_text_2()), which can […]

Read more
FreeBSD 12 — sugarcrm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sugarcrm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sugarcrm — multiple vulnerabilities Related CVEs: CVE-2017-14508 CVE-2017-14509 CVE-2017-14510 Upstream summary: sugarcrm developers report: An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and […]

Read more
openSUSE Tumbleweed — libqpid-proton11 — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libqpid-proton11 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1074-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-0223 Upstream summary: While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language […]

Read more
FreeBSD 12 — fr-cups-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — fr-cups-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cups-base — HPGL buffer overflow vulnerability Related CVEs: CVE-2004-1267 Upstream summary: Ariel Berkman has discovered a buffer overflow vulnerability in CUPS's HPGL input driver. This vulnerability could be exploited to […]

Read more
Ubuntu 16.04 — librsvg — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — librsvg — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4436-2 Related CVEs: https://launchpad.net/bugs/1889206 CVE-2017-11464 CVE-2019-20446 Upstream summary: USN-4436-1 fixed a vulnerability in librsvg. The upstream fix caused a regression when parsing certain SVG files. This update backs out the […]

Read more
Ubuntu 16.04 — ssvnc — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ssvnc — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4547-2 Related CVEs: CVE-2018-20020 CVE-2018-20021 CVE-2018-20022 CVE-2018-20024 Upstream summary: It was discovered that the LibVNCClient vendored in SSVNC incorrectly handled certain packet lengths. A remote attacker could possibly use this […]

Read more
openSUSE Tumbleweed — python-logilab-common — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python-logilab-common — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0301-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-1838 CVE-2014-1839 Upstream summary: The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and […]

Read more
CHAT