Logging Monitoring

Debian 11 — lava — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lava — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-12563 CVE-2018-12564 CVE-2018-12565 CVE-2022-42902 CVE-2022-44641 Upstream summary: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to […]

Read more
Ubuntu 18.04 — libreoffice — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libreoffice — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 October 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6023-1 Related CVEs: CVE-2022-38745 CVE-2020-12801 CVE-2020-12803 CVE-2022-26305 CVE-2022-26306 CVE-2022-26307 CVE-2022-3140 CVE-2021-25636  +6 more Upstream summary: It was discovered that LibreOffice may be configured to add an empty entry to the […]

Read more
Oracle Linux 9 — python-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — python-setuptools — vulnerability — patch and remediation guide (ELSA-2023-0952)

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-0952 Related CVEs: CVE-2022-40897 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Oracle Linux 8 — java-1.8.0-openjdk — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — java-1.8.0-openjdk — vulnerability — patch and remediation guide (ELSA-2022-7006)

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-7006 Related CVEs: CVE-2022-21626 CVE-2022-21628 CVE-2022-21619 CVE-2022-21624 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches […]

Read more
How to Set Up Remote Desktop Gateway on Windows Server 2016 — step-by-step Windows Server 2016 tutorial on Progressive Robot

How to Set Up Remote Desktop Gateway on Windows Server 2016

How to Set Up Windows Server 2016 Remote Desktop Gateway Remote Desktop Gateway (RD Gateway) is a role service in Windows Server 2016 Remote Desktop Services that enables authorised users to connect to internal network resources through HTTPS. Instead of exposing RDP port 3389 directly to the internet (which is a major security risk), RD […]

Read more
IBM AIX 7.2 — CVE-2022-22371 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2022-22371 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 9 October 2022 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2022-22371, IBM Support Bulletin CVE: CVE-2022-22371 NVD summary: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to […]

Read more
FreeBSD 13 — krb5-beta — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — krb5-beta — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: krb5 — heap buffer overflow vulnerability in libkadm5srv Related CVEs: CVE-2004-1189 Upstream summary: A MIT krb5 Security Advisory reports: The MIT Kerberos 5 administration library (libkadm5srv) contains a heap buffer […]

Read more
FreeBSD 13 — libXdmcp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libXdmcp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libXdmcp — insufficient entropy generating session keys Related CVEs: CVE-2017-2625 Upstream summary: The freedesktop and x.org project reports: It was discovered that libXdmcp before 1.1.3 used weak entropy to generate […]

Read more
Common Problems 120504

Debian 11 interrupted dpkg Requires Manual Configuration

🟠 High   ⏱ 5–30 min  Last verified: 9 October 2022 Affected versions: Debian 11 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
FreeBSD 13 — php70-wddx — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php70-wddx — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-8874 CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772  +1 more Upstream summary: The PHP Group reports: Please reference CVE/URL list for details Table of […]

Read more
CHAT