Package Management

Debian 11 — ircd-hybrid — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ircd-hybrid — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-4016 CVE-2010-0300 CVE-2013-0238 Upstream summary: Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, […]

Read more
Ubuntu 14.04 — apport — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — apport — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2022 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5122-2 Related CVEs: https://launchpad.net/bugs/1948657 CVE-2021-3709 CVE-2021-3710 CVE-2021-32547 CVE-2021-32548 CVE-2021-32549 CVE-2021-32550 CVE-2021-32551  +12 more Upstream summary: USN-5122-1 fixed a vulnerability in Apport. This update provides the corresponding update for Ubuntu 14.04 […]

Read more
Oracle Linux 8 — Unbreakable Enterprise kernel-container — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — Unbreakable Enterprise kernel-container — vulnerability — patch and remediation guide (ELSA-2021-9623)

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2021-9623 Related CVEs: CVE-2021-41864 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
How to Set Up Fail2ban on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Set Up Fail2ban on FreeBSD 13

Introduction How to Set Up Fail2ban on FreeBSD 13 is a core administration task for any FreeBSD 13 server operator. FreeBSD 13 ships with the 15.0-RELEASE kernel, ZFS as the default root filesystem, Capsicum capability sandboxing improvements, and an updated ports tree. Unlike Linux distributions, FreeBSD uses rc(8) for service management, pf for packet filtering, […]

Read more
Oracle Linux 8 — ELSA-2022-9074-1: thunderbird — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — ELSA-2022-9074-1: thunderbird — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9074-1 Related CVEs: CVE-2022-46878 CVE-2022-46872 CVE-2022-46874 CVE-2022-46882 CVE-2022-46881 CVE-2022-46880 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
FreeBSD 13 — py34-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py34-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Django — password hash disclosure Related CVEs: CVE-2014-0472 CVE-2014-0473 CVE-2014-0474 CVE-2014-0480 CVE-2014-0481 CVE-2014-0482 CVE-2014-0483 CVE-2015-0219  +12 more Upstream summary: Django release notes: CVE-2018-16984: Password hash disclosure to "view only" admin […]

Read more
Debian 10 — rails — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — rails — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8162 CVE-2021-22880 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
How to Install Kubernetes with kubeadm on RHEL 8 — step-by-step RHEL 8 tutorial on Progressive Robot

How to Install Kubernetes with kubeadm on RHEL 8

Kubernetes has become the de facto standard for container orchestration, and RHEL 8 provides a stable, enterprise-grade foundation for running production Kubernetes clusters. In this tutorial you will walk through a complete kubeadm-based installation on RHEL 8, from preparing the host operating system through initialising the control-plane node and connecting worker nodes via a Flannel […]

Read more
IBM AIX 7.1 — CVE-2021-38982 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2021-38982 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 18 January 2022 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2021-38982, IBM Support Bulletin CVE: CVE-2021-38982 NVD summary: IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code […]

Read more
FreeBSD 12 — pglogical — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pglogical — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pglogical — shell command injection in pglogical.create_subscription() Related CVEs: CVE-2021-3515 Upstream summary: 2ndQuadrant reports: Fix pg_dump/pg_restore execution (CVE-2021-3515) Correctly escape the connection string for both pg_dump and pg_restore so that […]

Read more
CHAT