Logging Monitoring

FreeBSD 13 — avahi-sharp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — avahi-sharp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: avahi — denial of service Related CVEs: CVE-2010-2244 CVE-2011-1002 Upstream summary: Avahi developers reports: A vulnerability has been reported in Avahi, which can be exploited by malicious people to cause […]

Read more
FreeBSD 13 — sdl_image — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sdl_image — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sdl_image — buffer overflow vulnerabilities Related CVEs: CVE-2007-6697 CVE-2008-0544 Upstream summary: Secunia reports: Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a […]

Read more
FreeBSD 13 — acme.sh — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — acme.sh — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: acme.sh — closes potential remote vuln Upstream summary: Neil Pang reports: HiCA was injecting arbitrary code/commands into the certificate obtaining process and acme.sh is running them on the client machine. […]

Read more
Oracle Linux 8 — pki-core:10.6 and pki-deps:10.6 security, bug fix, and — enhancement update — new behaviour and fixes — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — pki-core:10.6 and pki-deps:10.6 security, bug fix, and — enhancement update — new behaviour and fixes (ELSA-2021-1775)

🟡 Medium   ⏱ 10–30 min  Last verified: 9 March 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2021-1775 Related CVEs: CVE-2020-1695 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 11 — libpar-packer-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libpar-packer-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-4114 Upstream summary: The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and […]

Read more
Alpine Linux edge — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 2.9-r5 📖 ~4 min read  •  Source: Alpine secdb entry — wpa_supplicant 2.9-r5 Related CVEs: CVE-2019-16275 CVE-2021-30004 CVE-2021-27803 CVE-2021-0326 CVE-2019-11555 CVE-2019-9494 CVE-2019-9495 CVE-2019-9497  +12 more Upstream summary: Alpine main repository for vedge ships wpa_supplicant 2.9-r5 which […]

Read more
Debian 11 — node-hosted-git-info — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-hosted-git-info — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-23362 Upstream summary: The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The […]

Read more
Debian 11 — mimedefang — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mimedefang — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-14102 Upstream summary: MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by […]

Read more
Debian 11 — t-coffee — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — t-coffee — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-8621 Upstream summary: t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
CHAT