Operations

Debian 11 — g810-led — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — g810-led — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-46338 Upstream summary: g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process […]

Read more
How to Configure Drone CI on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Configure Drone CI on Debian 11

Introduction Debian 11 Bullseye is built around the ethos of stability and free software. Setting up configure drone ci on debian 11 on Bullseye leverages the same proven Debian packaging system that powers millions of servers worldwide, while benefiting from the latest upstream releases included in the Bullseye freeze. Follow each step carefully and the […]

Read more
Ubuntu 20.04 — ruby-image-processing — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — ruby-image-processing — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6675-1 Related CVEs: CVE-2022-24720 Upstream summary: It was discovered that ImageProcessing incorrectly handled series of operations that are coming from unsanitised inputs. If a user or an automated system were […]

Read more
Debian 11 — kcron — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kcron — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-24986 Upstream summary: KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be […]

Read more
Ubuntu 18.04 — ecdsautils — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — ecdsautils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6239-1 Related CVEs: CVE-2022-24884 Upstream summary: It was discovered that ECDSA Util did not properly verify certain signature values. An attacker could possibly use this issue to bypass signature verification. […]

Read more
Oracle Linux 9 — libtirpc — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — libtirpc — vulnerability — patch and remediation guide (ELSA-2022-8400)

🟡 Medium   ⏱ 10–30 min  Last verified: 11 October 2022 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-8400 Related CVEs: CVE-2021-46828 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
IBM AIX 7.1 — CVE-2022-35717 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-35717 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 11 October 2022 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-35717, IBM Support Bulletin CVE: CVE-2022-35717 NVD summary: "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. […]

Read more
IBM AIX 7.3 — CVE-1999-0089 — buffer overflow — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-1999-0089 — buffer overflow — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 10 October 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-1999-0089, IBM PSIRT advisory page CVE: CVE-1999-0089 NVD summary: Buffer overflow in AIX libDtSvc library can allow local users to gain root access. References: exchange.xforce.ibmcloud.com/vulnerabilities/CVE   exchange.xforce.ibmcloud.com/vulnerabilities/CVE Table of contents Symptom & […]

Read more
FreeBSD 13 — postgresql96-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql96-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL vulnerabilities Related CVEs: CVE-2016-5423 CVE-2016-5424 Upstream summary: The PostgreSQL project reports: Security Fixes nested CASE expressions + database and role names with embedded special characters CVE-2017-7484: selectivity estimators bypass […]

Read more
CHAT