Package Management

Debian 11 — kio — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-6410 Upstream summary: kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, […]

Read more
Debian 11 — samhain — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — samhain — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2409 CVE-2004-2410 CVE-2009-4810 Upstream summary: Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t update"), might allow attackers to execute […]

Read more
SLES 15 — permissions — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — permissions — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 November 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2345-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-31252 CVE-2019-3687 CVE-2019-3690 CVE-2020-8013 Upstream summary: A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE […]

Read more
Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide (ELSA-2022-9727)

🟠 High   ⏱ 15–60 min  Last verified: 24 November 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9727 Related CVEs: CVE-2022-21385 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Oracle Linux 9 — openssl — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — openssl — vulnerability — patch and remediation guide (ELSA-2022-9751)

🟡 Medium   ⏱ 10–30 min  Last verified: 24 November 2022 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9751 Related CVEs: CVE-2022-2068 CVE-2022-2097 CVE-2022-1473 CVE-2022-1292 CVE-2022-1343 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative […]

Read more
Alpine Linux edge — firefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — firefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 99.0-r0 📖 ~4 min read  •  Source: Alpine secdb entry — firefox 99.0-r0 Related CVEs: CVE-2022-1097 CVE-2022-24713 CVE-2022-28281 CVE-2022-28282 CVE-2022-28283 CVE-2022-28284 CVE-2022-28285 CVE-2022-28286  +12 more Upstream summary: Alpine community repository for vedge ships firefox 99.0-r0 which […]

Read more
IBM AIX 7.3 — CVE-1999-0057 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-1999-0057 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 23 November 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-1999-0057, IBM PSIRT advisory page CVE: CVE-1999-0057 NVD summary: Vacation program allows command execution by remote users through a sendmail command. References: www1.itrc.hp.com/service/cki/docDisplay.do?docId   www1.itrc.hp.com/service/cki/docDisplay.do?docId Table of contents Symptom & Impact Environment […]

Read more
Debian 11 — foo2zjs — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — foo2zjs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-2684 Upstream summary: foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which […]

Read more
Debian 11 — liquidsoap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — liquidsoap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4965 Upstream summary: liguidsoap.py in liguidsoap 0.3.8.1+2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/liguidsoap.liq, (2) /tmp/lig.#####.log, and (3) /tmp/emission.ogg temporary files. […]

Read more
CHAT