Package Management

Ubuntu 16.04 — jhead — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — jhead — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 October 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6113-1 Related CVEs: CVE-2018-6612 CVE-2021-28275 CVE-2021-28277 CVE-2021-3496 https://launchpad.net/bugs/2020068 CVE-2021-34055 CVE-2022-41751 CVE-2019-1010301  +7 more Upstream summary: It was discovered that Jhead did not properly handle certain crafted images while processing the […]

Read more
How to Configure Gitea Self-Hosted Git Service on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Configure Gitea Self-Hosted Git Service on Debian 11

Introduction Deploying configure gitea self-hosted git service on debian 11 on a Debian 11 Bullseye machine is straightforward thanks to Debian’s policy-compliant packaging. Unlike rpm-based distributions, Debian stores configuration helpers in /etc/default/, uses update-rc.d for older init scripts, and provides dpkg-reconfigure for interactive package configuration. This tutorial stays on the systemd path throughout. Prerequisites You […]

Read more
SLES 15 — libconfuse0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libconfuse0 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 October 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3331-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40320 Upstream summary: cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
SLES 15 — libinput10 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libinput10 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 October 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1305-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-1215 Upstream summary: A format string vulnerability was found in libinput Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
SLES 15 — libpcre2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libpcre2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 October 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1680-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-1587 CVE-2022-41409 CVE-2019-20454 CVE-2017-8786 Upstream summary: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This […]

Read more
How to Install HashiCorp Vault for Secrets Management on RHEL 7 — step-by-step RHEL 7 tutorial on Progressive Robot

How to Install HashiCorp Vault for Secrets Management on RHEL 7

How to Install HashiCorp Vault for Secrets Management on RHEL 7 HashiCorp Vault is an open-source tool for securely storing and tightly controlling access to tokens, passwords, certificates, API keys, and other secrets throughout the software lifecycle. Unlike storing secrets in configuration files or environment variables, Vault provides a central, audited, and access-controlled secrets store […]

Read more
How to Use NIS+ on IBM AIX 7.3 — step-by-step IBM AIX 7.3 tutorial on Progressive Robot

How to Use NIS+ on IBM AIX 7.3

Introduction IBM AIX 7.3 is the latest release of IBM’s enterprise-grade UNIX operating system, running on IBM Power Systems hardware. Known for its reliability, security, and performance in mission-critical environments, AIX 7.3 introduces enhanced virtualization, security hardening, and cloud integration features. This guide covers how to use nis+ on IBM AIX 7.3 with practical examples […]

Read more
FreeBSD 12 — seatd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — seatd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 October 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: seatd-launch — remove files with escalated privileges with SUID Related CVEs: CVE-2021-41387 CVE-2022-25643 Upstream summary: Kenny Levinsen reports: seatd-launch could use a user-specified socket path instead of the internally generated […]

Read more
Debian 11 — gnome-shell — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gnome-shell — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-4000 CVE-2012-4427 CVE-2013-7220 CVE-2013-7221 CVE-2014-7300 CVE-2017-8288 CVE-2019-3820 CVE-2020-17489  +1 more Upstream summary: gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local […]

Read more
CHAT