Package Management

Debian 11 — asn1c — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — asn1c — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-12966 CVE-2020-23910 CVE-2020-23911 Upstream summary: The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a […]

Read more
Ubuntu 18.04 — php-pear — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — php-pear — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2021 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5027-1 Related CVEs: CVE-2021-32610 CVE-2020-36193 CVE-2020-28948 CVE-2020-28949 CVE-2018-1000888 Upstream summary: It was discovered that PEAR incorrectly handled symbolic links in archives. A remote attacker could possibly use this issue to […]

Read more
SLES 12 — npm10 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm10 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 31 December 2021 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:2790-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-22930 CVE-2019-9514 CVE-2019-9515 CVE-2019-9518 CVE-2020-11080 CVE-2020-7774 CVE-2020-8252 CVE-2020-8265  +12 more Upstream summary: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free […]

Read more
How to Set Up a Certificate Authority with OpenSSL on RHEL 7 — step-by-step RHEL 7 tutorial on Progressive Robot

How to Set Up a Certificate Authority with OpenSSL on RHEL 7

How to Set Up a Certificate Authority with OpenSSL on RHEL 7 A Private Certificate Authority (CA) is essential infrastructure for any organization that needs to issue and manage TLS certificates for internal services, VPNs, mutual TLS authentication, or code signing — without relying on commercial CAs or exposing internal hostnames to the public internet. […]

Read more
IBM AIX 7.1 — CVE-2021-29692 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2021-29692 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 30 December 2021 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2021-29692, IBM Support Bulletin CVE: CVE-2021-29692 NVD summary: IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport […]

Read more
How to Configure OPcache for PHP on CentOS Stream 9 — step-by-step CentOS Stream 9 tutorial on Progressive Robot

How to Configure OPcache for PHP on CentOS Stream 9

Introduction Setting up configure opcache for php on centos stream 9 on a CentOS Stream 9 server is a common task for system administrators, DevOps engineers, and site reliability engineers. This guide explains how to Configure OPcache for PHP on CentOS Stream 9, with all the commands you need, the SELinux and firewalld considerations to […]

Read more
IBM AIX 7.1 — CVE-2021-29810 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.1

IBM AIX 7.1 — CVE-2021-29810 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 30 December 2021 Affected versions: IBM AIX 7.1 📖 ~4 min read  •  Source: NVD CVE-2021-29810, IBM Support Bulletin CVE: CVE-2021-29810 NVD summary: IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript […]

Read more
FreeBSD 13 — mod_access_referer — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mod_access_referer — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_access_referer — null pointer dereference vulnerability Related CVEs: CVE-2003-1054 Upstream summary: A malformed Referer header field causes the Apache ap_parse_uri_components function to discard it with the result that a pointer […]

Read more
FreeBSD 13 — gcpio — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gcpio — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GNU cpio — multiple vulnerabilities Related CVEs: CVE-2014-9112 CVE-2015-1197 CVE-2016-2037 CVE-2019-14866 Upstream summary: Sergey Poznyakoff reports: This stable release fixes several potential vulnerabilities CVE-2015-1197: cpio, when using the –no-absolute-filenames option, […]

Read more
FreeBSD 13 — linux-f10-curl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-f10-curl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cURL — inappropriate GSSAPI delegation Related CVEs: CVE-2011-2192 Upstream summary: cURL reports: When doing GSSAPI authentication, libcurl unconditionally performs credential delegation. This hands the server a copy of the client's […]

Read more
CHAT