Linux

SLES 15 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache2-mod_nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 March 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2013:1926-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4566 CVE-2015-5244 CVE-2016-3099 Upstream summary: mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting […]

Read more
openSUSE Tumbleweed — python36-websockets — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python36-websockets — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2854-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1000518 Upstream summary: aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured […]

Read more
Debian 9 — quagga — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — quagga — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 March 2019 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-16227 CVE-2018-5379 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
Arch Linux — mupdf — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — mupdf — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201805-4 Related CVEs: CVE-2018-6544 CVE-2018-6192 CVE-2018-6187 CVE-2018-5686 CVE-2018-1000051 CVE-2017-17858 CVE-2017-15587 CVE-2017-14687  +2 more Upstream summary: Type: multiple issues. Status: Fixed. Affected: 1.12.0-2. Fixed in: 1.13.0-1. Group: AVG-609. Table of contents […]

Read more
Ubuntu 14.04 — libvirt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libvirt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 March 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4047-2 Related CVEs: CVE-2019-10161 CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2019-11091 https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/MDS CVE-2018-1064 CVE-2018-3639  +12 more Upstream summary: USN-4047-1 fixed a vulnerability in libvirt. This update provides the corresponding update for Ubuntu 14.04 […]

Read more
Gentoo Linux — app-shells/rssh — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Gentoo Linux

Gentoo Linux — app-shells/rssh — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Gentoo Linux 📖 ~4 min read  •  Source: Gentoo GLSA GLSA-202007-29 Related CVEs: CVE-2019-1000018 CVE-2019-3463 CVE-2019-3464 Upstream summary: Multiple vulnerabilities have been discovered in rssh. Please review the CVE identifiers referenced below for details. Table of contents Symptom & Impact Environment & […]

Read more
Arch Linux — mupdf-tools — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — mupdf-tools — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201805-7 Related CVEs: CVE-2018-6544 CVE-2018-6192 CVE-2018-6187 CVE-2018-5686 CVE-2018-1000051 CVE-2017-17858 CVE-2017-15587 CVE-2017-14687  +2 more Upstream summary: Type: multiple issues. Status: Fixed. Affected: 1.12.0-2. Fixed in: 1.13.0-1. Group: AVG-688. Table of contents […]

Read more
Ubuntu 14.04 — texlive-bin — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — texlive-bin — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3788-1 Related CVEs: CVE-2015-5700 CVE-2018-17407 Upstream summary: Jakub Wilk discovered that Tex Live incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. This issue […]

Read more
Ubuntu 14.04 — vtk — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — vtk — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2019 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4852-1 Related CVEs: CVE-2018-20843 CVE-2019-15903 Upstream summary: It was discovered that VTK incorrectly handled certain XML files in the embedded Expat library. An attacker could possibly use this issue to […]

Read more
SLES 15 — openvswitch — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — openvswitch — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 March 2019 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-3449 Upstream summary: Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary […]

Read more
CHAT