Operations

FreeBSD 13 — unace — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — unace — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: unace — multiple vulnerabilities Related CVEs: CVE-2005-0160 CVE-2005-0161 Upstream summary: Ulf Härnhammar reports: There are buffer overflows when extracting, testing or listing specially prepared ACE archives. There are directory traversal […]

Read more
IBM AIX 7.1 — CVE-2022-35646 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2022-35646 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 22 April 2022 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2022-35646, IBM Support Bulletin CVE: CVE-2022-35646 NVD summary: IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using […]

Read more
FreeBSD 13 — libadplug — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libadplug — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libadplug — Various vulnerabilities Related CVEs: CVE-2019-14690 CVE-2019-14691 CVE-2019-14692 CVE-2019-14732 CVE-2019-14733 CVE-2019-14734 CVE-2019-15151 Upstream summary: Malvineous on Github reports: This release fixes the following security issues: buffer overflow in .bmf […]

Read more
AlmaLinux 8 — oci-systemd-hook — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — oci-systemd-hook — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2021:0705 Related CVEs: CVE-2021-20188 CVE-2020-10696 CVE-2020-7039 CVE-2019-16884 CVE-2019-18466 CVE-2019-9512 CVE-2019-9514 CVE-2019-10214  +3 more Upstream summary: The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): […]

Read more
FreeBSD 13 — py39-markdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-markdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-markdown2 — regular expression denial of service vulnerability Related CVEs: CVE-2020-11888 CVE-2021-26813 Upstream summary: Ben Caller reports: markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of […]

Read more
FreeBSD 12 — rpm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rpm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rpm4 — Multiple Vulnerabilities Related CVEs: CVE-2021-3521 CVE-2021-35938 CVE-2021-35939 Upstream summary: rpm project reports: Fix intermediate symlinks not verified (CVE-2021-35939). Fix subkey binding signatures not checked on PGP public keys […]

Read more
FreeBSD 13 — shotwell — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — shotwell — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shotwell — failure to encrypt authentication Upstream summary: Jens Georg reports: I have just released Shotwell 0.24.5 and 0.25.4 which turn on HTTPS encryption all over the publishing plugins. Users […]

Read more
Debian 11 — xfce4-terminal — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — xfce4-terminal — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-3770 Upstream summary: The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as […]

Read more
openSUSE Tumbleweed — python39-py — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — python39-py — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:338-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-42969 Upstream summary: The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a […]

Read more
Debian 11 — rubocop — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rubocop — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-8418 Upstream summary: RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other […]

Read more
CHAT