Package Management

Debian 11 — golang-github-containernetworking-plugins — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-containernetworking-plugins — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-10749 Upstream summary: A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A […]

Read more
How to Set Up the ELK Stack on RHEL 9 — step-by-step RHEL 9 tutorial on Progressive Robot

How to Set Up the ELK Stack on RHEL 9

The ELK Stack — Elasticsearch, Logstash, and Kibana — is a battle-tested open-source platform for centralizing, parsing, and visualizing log data at scale. Elasticsearch stores and indexes logs, Logstash ingests and transforms them, and Kibana provides a browser-based interface for searching and dashboarding. Running the ELK Stack on RHEL 9 gives you a self-hosted alternative […]

Read more
How to Set Up DRBD Block Replication on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Set Up DRBD Block Replication on Debian 11

Introduction Deploying set up drbd block replication on debian 11 on a Debian 11 Bullseye machine is straightforward thanks to Debian’s policy-compliant packaging. Unlike rpm-based distributions, Debian stores configuration helpers in /etc/default/, uses update-rc.d for older init scripts, and provides dpkg-reconfigure for interactive package configuration. This tutorial stays on the systemd path throughout. Prerequisites Ensure […]

Read more
Debian 11 — openocd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — openocd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-5704 Upstream summary: Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to […]

Read more
Debian 11 — libusbmuxd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libusbmuxd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5104 Upstream summary: The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by […]

Read more
Debian 11 — bcron — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — bcron — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-6110 Upstream summary: bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify […]

Read more
Ubuntu 18.04 — h2database — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — h2database — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2022 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6834-1 Related CVEs: CVE-2021-42392 CVE-2022-23221 Upstream summary: It was discovered that H2 was vulnerable to deserialization of untrusted data. An attacker could possibly use this issue to execute arbitrary code. […]

Read more
IBM AIX 7.3 — CVE-2022-30608 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2022-30608 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 13 August 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2022-30608, IBM Support Bulletin CVE: CVE-2022-30608 NVD summary: "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from […]

Read more
Oracle Linux 8 — go-toolset:ol8 security, bug fix, and — enhancement update — new behaviour and fixes — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — go-toolset:ol8 security, bug fix, and — enhancement update — new behaviour and fixes (ELSA-2019-3433)

🟡 Medium   ⏱ 10–30 min  Last verified: 12 August 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2019-3433 Related CVEs: CVE-2019-14809 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT