Package Management

Debian 11 — dist — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dist — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4949 Upstream summary: dist 3.5 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/cil#####, (b) /tmp/pdo#####, and (c) /tmp/pdn##### temporary files, related to […]

Read more
FreeBSD 12 — py311-WsgiDAV — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py311-WsgiDAV — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-WsgiDAV — XSS vulnerability Related CVEs: CVE-2022-41905 Upstream summary: Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. Table of contents Symptom […]

Read more
Debian 11 — metview — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — metview — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-17515 Upstream summary: etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct […]

Read more
Debian 11 — fence-agents — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fence-agents — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-0104 CVE-2019-10153 Upstream summary: In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL […]

Read more
Alpine Linux edge — perl-image-exiftool — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — perl-image-exiftool — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 12.40-r0 📖 ~4 min read  •  Source: Alpine secdb entry — perl-image-exiftool 12.40-r0 Related CVEs: CVE-2022-23935 CVE-2021-22204 Upstream summary: Alpine community repository for vedge ships perl-image-exiftool 12.40-r0 which addresses CVE-2022-23935. Table of contents Symptom & Impact […]

Read more
Debian 11 — rrdtool — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rrdtool — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-2131 CVE-2014-6262 Upstream summary: Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) […]

Read more
SLES 12 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 2 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1018-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29155 CVE-2020-12243 CVE-2020-25692 CVE-2020-36221 CVE-2020-36222 CVE-2020-36223 CVE-2020-36224 CVE-2020-36225  +12 more Upstream summary: In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability […]

Read more
IBM AIX 7.2 — CVE-2022-40750 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2022-40750 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 1 December 2022 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2022-40750, IBM Support Bulletin CVE: CVE-2022-40750 NVD summary: IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web […]

Read more
FreeBSD 12 — py37-slixmpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-slixmpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 December 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-slixmpp — incomplete SSL certificate validation Related CVEs: CVE-2019-1000021 CVE-2022-45197 Upstream summary: Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server […]

Read more
CHAT