Linux

Debian 9 — ikiwiki — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — ikiwiki — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 April 2019 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-9187 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Ubuntu 18.04 — librsvg — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — librsvg — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2019 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4436-2 Related CVEs: https://launchpad.net/bugs/1889206 CVE-2017-11464 CVE-2019-20446 Upstream summary: USN-4436-1 fixed a vulnerability in librsvg. The upstream fix caused a regression when parsing certain SVG files. This update backs out the […]

Read more
Amazon Linux 2 — SDL — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — SDL — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2019-1375 Related CVEs: CVE-2019-13616 CVE-2019-14906 CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577  +5 more Upstream summary: A heap-based buffer overflow flaw, in SDL while copying an existing surface into a new […]

Read more
SLES 15 — virt-install — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — virt-install — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2019-10183 Upstream summary: Virt-install(1) utility used to provision new virtual machines has introduced an option '–unattended' to create VMs without user interaction. This option accepts […]

Read more
SLES 15 — xdg-utils — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xdg-utils — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 March 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1497-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-18266 Upstream summary: The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment […]

Read more
SLES 15 — file — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — file — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 31 March 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2020:177-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-18218 CVE-2012-1571 CVE-2014-3710 CVE-2014-8116 CVE-2014-8117 CVE-2017-1000249 CVE-2019-8905 CVE-2019-8906  +2 more Upstream summary: cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of […]

Read more
openSUSE Tumbleweed — gitolite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — gitolite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2018:3035-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-16976 CVE-2018-20683 Upstream summary: Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that […]

Read more
openSUSE Tumbleweed — python36-python-gnupg — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-python-gnupg — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2019:0143-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-6690 Upstream summary: python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg […]

Read more
Ubuntu 16.04 — kconfig — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — kconfig — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4100-1 Related CVEs: CVE-2016-6232 CVE-2019-14744 Upstream summary: It was discovered that KConfig and KDE libraries have a vulnerability where an attacker could hide malicious code under desktop and configuration files. […]

Read more
Ubuntu 16.04 — vcftools — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — vcftools — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 March 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3974-1 Related CVEs: CVE-2018-11099 CVE-2018-11129 CVE-2018-11130 Upstream summary: It was discovered that VCFtools improperly handled certain input. If a user was tricked into opening a crafted input file, VCFtools could […]

Read more
CHAT