Linux

Debian 11 — golang-github-russellhaering-goxmldsig — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-russellhaering-goxmldsig — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15216 CVE-2020-7711 Upstream summary: In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature […]

Read more
Ubuntu 14.04 — dbus — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — dbus — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2022 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5704-1 Related CVEs: CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 CVE-2020-12049 CVE-2019-12749 CVE-2015-0245 CVE-2014-7824 CVE-2014-3635  +7 more Upstream summary: It was discovered that DBus incorrectly handled messages with invalid type signatures. A local attacker […]

Read more
SLES 15 — libcaca0 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcaca0 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 7 July 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0754-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-30498 CVE-2021-30499 CVE-2022-0856 CVE-2021-3410 CVE-2018-20547 CVE-2018-20544 CVE-2018-20545 CVE-2018-20546  +2 more Upstream summary: A flaw was found in libcaca. A heap buffer overflow in export.c in […]

Read more
AlmaLinux 8 — perl-XML-Parser — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — perl-XML-Parser — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2026:7681 Related CVEs: CVE-2006-10002 CVE-2006-10003 Upstream summary: This module provides ways to parse XML documents. It is built on top of XML::Parser::Expat, which is a lower level interface to James Clark's expat […]

Read more
Ubuntu 14.04 — libcaca — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libcaca — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2022 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7943-1 Related CVEs: CVE-2022-0856 CVE-2021-30498 CVE-2021-30499 CVE-2021-3410 CVE-2018-20544 CVE-2018-20545 CVE-2018-20546 CVE-2018-20547  +2 more Upstream summary: Han Zheng discovered that libcaca incorrectly handled certain images. An attacker could possibly use this […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.238-182.422 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.238-182.422 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2021-064 Related CVEs: CVE-2021-40490 Upstream summary: No CVE associated with this advisory Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – […]

Read more
Debian 11 — ncompress — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ncompress — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2001-1413 CVE-2006-1168 CVE-2010-0001 Upstream summary: Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP […]

Read more
Ubuntu 22.04 — fossil — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — fossil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 July 2022 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6770-1 Related CVEs: https://launchpad.net/bugs/2064509 Upstream summary: USN-6729-1 fixed vulnerabilities in Apache HTTP Server. The update lead to the discovery of a regression in Fossil with regards to the handling of […]

Read more
Ubuntu 20.04 — usbredir — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — usbredir — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 July 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5784-1 Related CVEs: CVE-2021-3700 Upstream summary: It was discovered that usbredir incorrectly handled memory when serializing large amounts of data in the case of a slow or blocked destination. An […]

Read more
CHAT