Package Management

Debian 11 — commons-daemon — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — commons-daemon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-2729 Upstream summary: native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and […]

Read more
FreeBSD 13 — p5-HTML-Parser — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p5-HTML-Parser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-HTML-Parser — denial of service Related CVEs: CVE-2009-3627 Upstream summary: CVE reports: The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service […]

Read more
Debian 11 — audiolink — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — audiolink — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4942 Upstream summary: audiolink in audiolink 0.05 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/audiolink.db.tmp and (2) /tmp/audiolink.tb.tmp temporary files. Table […]

Read more
Debian 11 — octavia — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — octavia — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-17134 Upstream summary: Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and […]

Read more
How to Configure RAID 10 with mdadm on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Configure RAID 10 with mdadm on Debian 11

Introduction How to Configure RAID 10 with mdadm on Debian 11 is a fundamental operation for any administrator maintaining a Debian 11 Bullseye server. Debian 11 Bullseye ships with the Linux 6.12 kernel, updated toolchains, and a fully refreshed package archive — meaning version numbers, configuration file paths, and some dependency chains differ from Debian […]

Read more
Debian 11 — mini-httpd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mini-httpd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-4490 CVE-2015-1548 CVE-2017-17663 CVE-2018-18778 Upstream summary: mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, […]

Read more
Debian 11 — lava — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lava — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-12563 CVE-2018-12564 CVE-2018-12565 CVE-2022-42902 CVE-2022-44641 Upstream summary: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to […]

Read more
Ubuntu 18.04 — libreoffice — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libreoffice — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 October 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6023-1 Related CVEs: CVE-2022-38745 CVE-2020-12801 CVE-2020-12803 CVE-2022-26305 CVE-2022-26306 CVE-2022-26307 CVE-2022-3140 CVE-2021-25636  +6 more Upstream summary: It was discovered that LibreOffice may be configured to add an empty entry to the […]

Read more
Oracle Linux 9 — python-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — python-setuptools — vulnerability — patch and remediation guide (ELSA-2023-0952)

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-0952 Related CVEs: CVE-2022-40897 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Oracle Linux 8 — java-1.8.0-openjdk — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — java-1.8.0-openjdk — vulnerability — patch and remediation guide (ELSA-2022-7006)

🟡 Medium   ⏱ 10–30 min  Last verified: 10 October 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-7006 Related CVEs: CVE-2022-21626 CVE-2022-21628 CVE-2022-21619 CVE-2022-21624 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches […]

Read more
CHAT