Package Management

Debian 11 — ppp — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ppp — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1002 CVE-2006-2194 CVE-2008-5366 CVE-2008-5367 CVE-2014-3158 CVE-2015-3310 CVE-2018-11574 CVE-2020-8597  +2 more Upstream summary: Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial […]

Read more
Ubuntu 22.04 — pypy3 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — pypy3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 August 2022 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6524-1 Related CVEs: CVE-2022-37454 Upstream summary: Nicky Mouha discovered that PyPy incorrectly handled certain SHA-3 operations. An attacker could possibly use this issue to cause PyPy to crash, resulting in […]

Read more
SLES 12 — npm12 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm12 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 5 August 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2824-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-22940 CVE-2022-43548 CVE-2022-32212 CVE-2022-2097 CVE-2020-8172 CVE-2020-8277 CVE-2021-37701 CVE-2021-37712  +12 more Upstream summary: Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free […]

Read more
Gentoo Linux — app-shells/fish — vulnerability — patch and remediation guide — diagnosis and fix on Gentoo Linux

Gentoo Linux — app-shells/fish — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Gentoo Linux 📖 ~4 min read  •  Source: Gentoo GLSA GLSA-202309-10 Related CVEs: CVE-2022-20001 Upstream summary: A vulnerability have been discovered in Fish. Please review the CVE identifiers referenced below for details. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
FreeBSD 13 — pam_smb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pam_smb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Buffer overflow in pam_smb password handling Related CVEs: CVE-2003-0686 Upstream summary: Applications utilizing pam_smb can be compromised by any user who can enter a password. In many cases, this is […]

Read more
FreeBSD 13 — py39-joblib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-joblib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-joblib — arbitrary code execution Related CVEs: CVE-2022-21797 Upstream summary: jimlinntu reports: The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag […]

Read more
Oracle Linux 8 — ELSA-2020-5607-1: fapolicyd — bug fix update — issues resolved — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — ELSA-2020-5607-1: fapolicyd — bug fix update — issues resolved

🟠 High   ⏱ 15–60 min  Last verified: 4 August 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2020-5607-1 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
FreeBSD 13 — sane-backends — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sane-backends — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Sane — Multiple Vulnerabilities Related CVEs: CVE-2020-12861 CVE-2020-12862 CVE-2020-12863 CVE-2020-12864 CVE-2020-12865 CVE-2020-12866 CVE-2020-12867 Upstream summary: The Sane Project reports: epson2: fixes CVE-2020-12867 (GHSL-2020-075) and several memory management issues found while […]

Read more
FreeBSD 13 — tr-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tr-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2004-0752 CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading […]

Read more
CHAT