Linux

Alpine Linux edge — cabextract — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — cabextract — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 1.8-r0 📖 ~4 min read  •  Source: Alpine secdb entry — cabextract 1.8-r0 Related CVEs: CVE-2018-18584 Upstream summary: Alpine community repository for vedge ships cabextract 1.8-r0 which addresses CVE-2018-18584. Table of contents Symptom & Impact Environment […]

Read more
Amazon Linux 2 — wget — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — wget — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2019-1227 Related CVEs: CVE-2019-5953 CVE-2018-0494 Upstream summary: Buffer overflow in GNU Wget allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors. (CVE-2019-5953) […]

Read more
Arch Linux — lib32-libtasn1 — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — lib32-libtasn1 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201706-10 Related CVEs: CVE-2017-6891 Upstream summary: Type: arbitrary code execution. Status: Fixed. Affected: 4.10-1. Fixed in: 4.11-1. Group: AVG-286. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Amazon Linux 2 — bash — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — bash — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2020-1503 Related CVEs: CVE-2019-9924 Upstream summary: rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the […]

Read more
SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bzip2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2019 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SR:2010:018 (see also SUSE bugzilla) Related CVEs: CVE-2010-0405 CVE-2019-12900 CVE-2016-3189 Upstream summary: Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a […]

Read more
Alpine Linux edge — lame — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — lame — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 3.99.5-r6 📖 ~4 min read  •  Source: Alpine secdb entry — lame 3.99.5-r6 Related CVEs: CVE-2015-9099 CVE-2015-9100 CVE-2017-9410 CVE-2017-9411 CVE-2017-9412 CVE-2017-11720 Upstream summary: Alpine main repository for vedge ships lame 3.99.5-r6 which addresses CVE-2015-9099. Table of […]

Read more
Ubuntu 16.04 — keepalived — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — keepalived — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-3995-1 Related CVEs: CVE-2018-19115 Upstream summary: It was discovered that Keepalived incorrectly handled certain HTTP status response codes. A remote attacker could use this issue to cause Keepalived to crash, […]

Read more
Ubuntu 16.04 — graphite2 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — graphite2 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 January 2019 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5657-1 Related CVEs: CVE-2018-7999 CVE-2017-7771 CVE-2017-7772 CVE-2017-7773 CVE-2017-7774 CVE-2017-7775 CVE-2017-7776 CVE-2017-7777  +1 more Upstream summary: It was discovered that Graphite2 mishandled specially crafted files. An attacker could possibly use this […]

Read more
openSUSE Tumbleweed — ruby2.2-rubygem-RedCloth — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — ruby2.2-rubygem-RedCloth — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-6684 Upstream summary: Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or […]

Read more
Amazon Linux 2 — audiofile — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — audiofile — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2024-2601 Related CVEs: CVE-2015-7747 CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833  +11 more Upstream summary: Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows […]

Read more
CHAT