Linux

Debian 11 — caribou — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — caribou — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-3567 Upstream summary: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage […]

Read more
Debian 11 — libast — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libast — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-0224 Upstream summary: Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute […]

Read more
Debian 11 — openntpd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — openntpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5117 Upstream summary: OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp […]

Read more
How to Use Prometheus Blackbox Exporter for Endpoint Monitoring on RHEL 7 — step-by-step RHEL 7 tutorial on Progressive Robot

How to Use Prometheus Blackbox Exporter for Endpoint Monitoring on RHEL 7

How to Use Prometheus Blackbox Exporter for Endpoint Monitoring on RHEL 7 The Prometheus Blackbox Exporter probes external endpoints over HTTP, HTTPS, TCP, ICMP, and DNS from the perspective of an outside caller, making it an essential complement to node-level metrics collected by Node Exporter. While Node Exporter tells you about CPU load and memory […]

Read more
Ubuntu 14.04 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 September 2021 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5064-3 Related CVEs: CVE-2021-38185 CVE-2019-14866 CVE-2015-1197 CVE-2016-2037 CVE-2010-0624 CVE-2014-9112 Upstream summary: USN-5064-1 fixed a vulnerability in GNU. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: […]

Read more
SLES 12 — openexr — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — openexr — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 September 2021 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:14846-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-20298 CVE-2021-3479 CVE-2021-3605 CVE-2020-15304 CVE-2020-15305 CVE-2020-15306 CVE-2020-16587 CVE-2020-16588  +12 more Upstream summary: A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who […]

Read more
Oracle Linux 8 — cockpit security, bug fix, and — enhancement update — new behaviour and fixes — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — cockpit security, bug fix, and — enhancement update — new behaviour and fixes (ELSA-2022-2008)

🟡 Medium   ⏱ 10–30 min  Last verified: 27 September 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-2008 Related CVEs: CVE-2021-3660 CVE-2021-3698 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
CHAT