Package Management

Ubuntu 16.04 — hivex — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — hivex — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 October 2021 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5148-2 Related CVEs: CVE-2021-3504 Upstream summary: USN-5148-1 fixed a vulnerability in hivex. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: It […]

Read more
SLES 15 — ant — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ant — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 October 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-11979 CVE-2021-42550 CVE-2021-36373 CVE-2021-36374 CVE-2013-1571 CVE-2018-10886 CVE-2020-1945 Upstream summary: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so […]

Read more
Oracle Linux 8 — java-11-openjdk — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — java-11-openjdk — vulnerability — patch and remediation guide (ELSA-2021-1307)

🟡 Medium   ⏱ 10–30 min  Last verified: 23 October 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2021-1307 Related CVEs: CVE-2021-2163 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
FreeBSD 13 — postgresql-contrib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql-contrib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: postgresql-contrib — insecure temporary file creation Related CVEs: CVE-2004-0977 Upstream summary: The make_oidjoins_check script in the PostgreSQL RDBMS has insecure handling of temporary files, which could lead to an attacker […]

Read more
FreeBSD 13 — py310-suds — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-suds — vulnerable to symlink attacks Related CVEs: CVE-2013-2217 Upstream summary: SUSE reports: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries […]

Read more
FreeBSD 13 — enscript-a — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — enscript-a — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: enscript — arbitrary code execution vulnerability Related CVEs: CVE-2004-1184 CVE-2004-1185 CVE-2004-1186 CVE-2008-3863 CVE-2008-4306 Upstream summary: Ulf Harnhammar of Secunia Research reports: Stack-based buffer overflow in the read_special_escape function in src/psgen.c […]

Read more
How to Configure Prometheus AlertManager on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Configure Prometheus AlertManager on FreeBSD 13

Introduction FreeBSD 13 is a UNIX-derived operating system renowned for its network stack performance, ZFS integration, and Jail isolation primitives. Setting up configure prometheus alertmanager on freebsd 13 on FreeBSD 13 follows the rc.conf/service(8) paradigm rather than systemd, which means enabling a service and configuring its startup options are done differently from any Linux distribution. […]

Read more
Oracle Linux 8 — frr — security and stability fixes — required update — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — frr — security and stability fixes — required update (ELSA-2020-4619)

🟡 Medium   ⏱ 10–30 min  Last verified: 22 October 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2020-4619 Related CVEs: CVE-2020-12831 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
FreeBSD 13 — sogo2-activesync — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sogo2-activesync — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SOGo — SAML user authentication impersonation Related CVEs: CVE-2021-33054 Upstream summary: sogo.nu reports: SOGo was not validating the signatures of any SAML assertions it received. This means any actor with […]

Read more
CHAT