Logging Monitoring

Debian 11 — mpg123 — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mpg123 — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 September 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0577 CVE-2003-0865 CVE-2004-0805 CVE-2004-0982 CVE-2004-0991 CVE-2004-1284 CVE-2006-1655 CVE-2006-3355  +10 more Upstream summary: mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code […]

Read more
Debian 11 — suds — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 September 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-2217 Upstream summary: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a […]

Read more
How to Configure Multipath I/O on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Configure Multipath I/O on Debian 11

Introduction This guide explains how to Configure Multipath I/O on Debian 11 on Debian 11 Bullseye. Debian Bullseye uses systemd for service management, nftables as the underlying packet filter (with ufw or iptables front-ends still available), and AppArmor for mandatory access control. Every command is designed for a minimal Debian 11 install with the standard […]

Read more
Ubuntu 22.04 — grunt — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — grunt — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 September 2022 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5847-1 Related CVEs: CVE-2020-7729 CVE-2022-0436 CVE-2022-1537 Upstream summary: It was discovered that Grunt was not properly loading YAML files before parsing them. An attacker could possibly use this issue to […]

Read more
SLES 12 — apache2-mod_wsgi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — apache2-mod_wsgi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 September 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:3372-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-2255 Upstream summary: A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker […]

Read more
Oracle Linux 8 — pcre2 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — pcre2 — vulnerability — patch and remediation guide (ELSA-2022-5809)

🟡 Medium   ⏱ 10–30 min  Last verified: 13 September 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-5809 Related CVEs: CVE-2022-1586 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
FreeBSD 13 — pg_partman — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pg_partman — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PG Partition Manager — arbitrary code execution Related CVEs: CVE-2021-33204 Upstream summary: PG Partition Manager reports: In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code […]

Read more
FreeBSD 13 — kf5-kconfig — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — kf5-kconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: KDE Frameworks — malicious .desktop files execute code Related CVEs: CVE-2019-14744 Upstream summary: The KDE Community has released a security announcement: The syntax Key[$e]=$(shell command) in *.desktop files.directory files, and […]

Read more
CHAT