IT, Cloud & DevOps Blog

FreeBSD 12 — php55-gd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php55-gd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2013-7456 CVE-2015-4643 CVE-2015-4644 CVE-2015-8874 CVE-2015-8879 CVE-2016-3074 CVE-2016-4343 CVE-2016-5093  +12 more Upstream summary: PHP reports: Fixed bug #69975 (PHP segfaults when accessing nvarchar(max) defined columns) […]

Read more
FreeBSD 12 — plone — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — plone — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: plone — multiple vulnerabilities Related CVEs: CVE-2006-1711 CVE-2006-4249 CVE-2007-0240 CVE-2007-5741 CVE-2011-0720 Upstream summary: Plone.org reports: Versions Affected: All current Plone versions. Versions Not Affected: None. Nature of vulnerability: Allows creation […]

Read more
openSUSE Tumbleweed — discount — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — discount — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:0019-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11468 CVE-2018-12495 Upstream summary: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer […]

Read more
FreeBSD 12 — py33-djblets — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py33-djblets — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-djblets — Self-XSS vulnerability Upstream summary: Djblets Release Notes reports: A recently-discovered vulnerability in the datagrid templates allows an attacker to generate a URL to any datagrid page containing malicious […]

Read more
SLES 15 — libwps — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libwps — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:2485-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10583 CVE-2018-16858 Upstream summary: An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded […]

Read more
SLES 15 — tcpdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tcpdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 January 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1765-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-16301 CVE-2015-0261 CVE-2015-2153 CVE-2015-2154 CVE-2015-2155 CVE-2016-7922 CVE-2016-7923 CVE-2016-7924  +12 more Upstream summary: The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in […]

Read more
Ubuntu 14.04 — libsoup2.4 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libsoup2.4 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 January 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3701-1 Related CVEs: CVE-2018-12910 CVE-2017-2885 https://launchpad.net/bugs/1573494 Upstream summary: It was discovered that libsoup incorrectly handled certain cookie requests. An attacker could possibly use this to cause a denial of service. […]

Read more
Alpine Linux edge — sox — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — sox — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 14.4.2-r5 📖 ~4 min read  •  Source: Alpine secdb entry — sox 14.4.2-r5 Related CVEs: CVE-2017-13571 CVE-2017-11358 CVE-2017-15370 CVE-2017-11332 CVE-2017-11359 CVE-2017-15372 CVE-2017-13642 CVE-2017-18189  +10 more Upstream summary: Alpine community repository for vedge ships sox 14.4.2-r5 which […]

Read more
openSUSE Tumbleweed — derby — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — derby — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2005-4849 CVE-2015-1832 CVE-2006-7216 CVE-2006-7217 Upstream summary: Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter […]

Read more
FreeBSD 12 — nginx-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — nginx-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nginx-devel — multiple vulnerabilities Related CVEs: CVE-2009-2629 CVE-2012-2089 CVE-2013-2028 CVE-2013-2070 CVE-2013-4547 CVE-2014-0088 CVE-2014-0133 CVE-2014-3556  +12 more Upstream summary: The nginx project reports: nginx 1.31.0 fixes multiple security issues affecting HTTP/2 […]

Read more
CHAT