Package Management

Debian 11 — squashfs-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — squashfs-tools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-4024 CVE-2012-4025 CVE-2015-4645 CVE-2015-4646 CVE-2021-40153 CVE-2021-41072 Upstream summary: Stack-based buffer overflow in the get_component function in unsquashfs.c in unsquashfs in Squashfs 4.2 and earlier allows remote attackers to […]

Read more
Debian 11 — php-dompdf — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — php-dompdf — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-4879 CVE-2014-2383 CVE-2014-5011 CVE-2014-5012 CVE-2014-5013 CVE-2021-3838 CVE-2022-2400 Upstream summary: PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary PHP code […]

Read more
Debian 11 — node-jquery — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-jquery — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-11358 CVE-2020-11022 CVE-2020-11023 Upstream summary: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}…) because of Object.prototype pollution. If an unsanitized source […]

Read more
Debian 11 — libinfinity — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libinfinity — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-3886 Upstream summary: libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors. Table of contents Symptom & […]

Read more
Gentoo Linux — media-libs/openjpeg — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Gentoo Linux

Gentoo Linux — media-libs/openjpeg — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Gentoo Linux 📖 ~4 min read  •  Source: Gentoo GLSA GLSA-202209-04 Related CVEs: CVE-2021-29338 CVE-2022-1122 CVE-2018-21010 CVE-2019-12973 CVE-2020-15389 CVE-2020-27814 CVE-2020-27841 CVE-2020-27842  +3 more Upstream summary: Multiple vulnerabilities have been discovered in OpenJPEG. Please review the CVE identifiers referenced below for details. Table […]

Read more
Ubuntu 20.04 — rust-regex — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — rust-regex — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 May 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5610-1 Related CVEs: CVE-2022-24713 Upstream summary: Addison Crump discovered that rust-regex did not properly limit the complexity of the regular expressions (regex) it parses. An attacker could possibly use this […]

Read more
Oracle Linux 8 — GraalVM — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — GraalVM — vulnerability — patch and remediation guide (ELSA-2022-9650)

🟠 High   ⏱ 15–60 min  Last verified: 13 May 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9650 Related CVEs: CVE-2022-25647 CVE-2022-21540 CVE-2022-34169 CVE-2022-21541 CVE-2022-21549 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative […]

Read more
FreeBSD 13 — horde — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — horde — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: horde — XSS vulnerabilities Related CVEs: CVE-2005-0961 CVE-2005-3759 CVE-2006-1491 CVE-2006-2195 CVE-2006-3548 CVE-2015-8807 CVE-2016-2228 Upstream summary: The Horde Team reports: Fixed XSS vulnerabilities in menu bar and form renderer. Table of […]

Read more
CHAT