Logging Monitoring

FreeBSD 13 — ja-ppxp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-ppxp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ppxp — local root exploit Related CVEs: CVE-2005-0392 Upstream summary: A Debian Advisory reports: Jens Steube discovered that ppxp, yet another PPP program, does not release root privileges when opening […]

Read more
openSUSE Tumbleweed — audiofile — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — audiofile — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0940-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7747 CVE-2018-17095 CVE-2019-13147 CVE-2022-24599 CVE-2017-6828 CVE-2017-6830 CVE-2017-6832 CVE-2017-6834  +3 more Upstream summary: Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File […]

Read more
Debian 11 — node-object-path — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-object-path — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15256 CVE-2021-23434 CVE-2021-3805 Upstream summary: A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode […]

Read more
Debian 11 — php-horde-ldap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — php-horde-ldap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-3999 Upstream summary: The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN. Table of contents […]

Read more
Ubuntu 20.04 — bcel — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — bcel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7208-1 Related CVEs: CVE-2022-42920 Upstream summary: Felix Wilhelm discovered that Apache Commons BCEL APIs incorrectly handled parameters due to a memory issue. An attacker supplying malicious input could exploit this […]

Read more
SLES 15 — xscreensaver — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xscreensaver — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 January 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2641-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-34557 CVE-2015-8025 Upstream summary: XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows […]

Read more
IBM AIX 7.3 — CVE-2010-0960 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2010-0960 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 21 January 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2010-0960, IBM Support Bulletin CVE: CVE-2010-0960 NVD summary: Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors. References: aix.software.ibm.com/aix/efixes/security/qosmod_ […]

Read more
SLES 12 — finch — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — finch — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 January 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1664-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-26491 CVE-2009-2694 CVE-2010-0013 CVE-2011-3594 CVE-2012-6152 CVE-2017-2640 CVE-2009-2703 CVE-2009-3026  +12 more Upstream summary: An issue was discovered in Pidgin before 2.14.9. A remote attacker who can […]

Read more
Arch Linux — rabbitmq — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — rabbitmq — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-202106-17 Related CVEs: CVE-2021-22116 CVE-2021-32719 CVE-2021-32718 Upstream summary: Type: denial of service. Status: Fixed. Affected: 3.8.14-1. Fixed in: 3.8.16-1. Group: AVG-1966. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
CHAT