Package Management

Oracle Linux 8 — git — security and stability fixes — required update — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — git — security and stability fixes — required update (ELSA-2023-2859)

🟡 Medium   ⏱ 10–30 min  Last verified: 28 November 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-2859 Related CVEs: CVE-2022-29187 CVE-2022-39260 CVE-2022-24765 CVE-2022-39253 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches […]

Read more
FreeBSD 13 — php52-filter — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php52-filter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-filter — Denial of Service Related CVEs: CVE-2010-3710 Upstream summary: The following DoS condition in filter extension was fixed in PHP 5.3.4 and PHP 5.2.15: Stack consumption vulnerability in the […]

Read more
Debian 11 — giftrans — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — giftrans — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-45972 Upstream summary: The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. […]

Read more
How to Monitor Nginx with Prometheus on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Monitor Nginx with Prometheus on FreeBSD 13

Introduction This guide explains how to Monitor Nginx with Prometheus on FreeBSD 13 on FreeBSD 13. FreeBSD uses the pkg(8) binary package manager, rc.conf(5) for service startup configuration, and pf(4) as its primary packet filter. There is no SELinux or AppArmor — instead, FreeBSD provides the MAC (Mandatory Access Control) framework and Capsicum for fine-grained […]

Read more
Debian 11 — sredird — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — sredird — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2386 CVE-2004-2387 Upstream summary: Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via […]

Read more
FreeBSD 13 — compat5x-amd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — compat5x-amd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
Debian 11 — python-rsa — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-rsa — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-1494 CVE-2020-13757 CVE-2020-25658 Upstream summary: The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via […]

Read more
Debian 11 — ncftp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ncftp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1948 Upstream summary: NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local […]

Read more
Debian 11 — gzip — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gzip — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-1999-1332 CVE-2003-0367 CVE-2004-0970 CVE-2005-0758 CVE-2005-0988 CVE-2005-1228 CVE-2006-4334 CVE-2006-4335  +6 more Upstream summary: gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to […]

Read more
Debian 11 — calligra — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — calligra — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-3456 Upstream summary: Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a […]

Read more
CHAT