Package Management

Oracle Linux 8 — ULN registration wizard not displayed on first boot after an installation — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — ULN registration wizard not displayed on first boot after an installation

🟠 High   ⏱ 5–30 min  Last verified: 28 September 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: Oracle Bug 29939974 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
IBM AIX 7.2 — CVE-2021-39035 — xss — patch and remediation guide — diagnosis and fix on IBM AIX 7.2

IBM AIX 7.2 — CVE-2021-39035 — xss — patch and remediation guide

🟡 Medium   ⏱ 15–45 min  Last verified: 28 September 2021 Affected versions: IBM AIX 7.2 📖 ~4 min read  •  Source: NVD CVE-2021-39035, IBM Support Bulletin CVE: CVE-2021-39035 NVD summary: IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to cross-site scripting. This vulnerability allows […]

Read more
FreeBSD 13 — istio — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — istio — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Istio — Security vulnerabilities Related CVEs: CVE-2019-9900 CVE-2019-9901 Upstream summary: Istio reports: Two security vulnerabilities have recently been identified in the Envoy proxy. The vulnerabilities are centered on the fact […]

Read more
How to Set Up OpenLiteSpeed on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Set Up OpenLiteSpeed on FreeBSD 13

Introduction Deploying set up openlitespeed on freebsd 13 on a FreeBSD 13 machine differs from Linux in several important ways: packages come from the FreeBSD Ports Collection or the binary pkg repository, services are registered in /etc/rc.conf via sysrc(8), and firewall rules are written in pf.conf(5) syntax. This tutorial stays entirely within the standard base […]

Read more
Debian 11 — caribou — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — caribou — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-3567 Upstream summary: A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-locking applications that leverage […]

Read more
FreeBSD 13 — libav — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libav — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 September 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ffmpeg — multiple vulnerabilities Related CVEs: CVE-2014-8544 CVE-2014-9604 CVE-2015-3395 CVE-2015-3417 CVE-2015-5479 CVE-2015-6761 CVE-2015-6818 CVE-2015-6819  +12 more Upstream summary: NVD reports: The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does […]

Read more
Debian 11 — libast — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libast — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-0224 Upstream summary: Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute […]

Read more
Debian 11 — openntpd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — openntpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 September 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5117 Upstream summary: OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp […]

Read more
Ubuntu 14.04 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — cpio — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 September 2021 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5064-3 Related CVEs: CVE-2021-38185 CVE-2019-14866 CVE-2015-1197 CVE-2016-2037 CVE-2010-0624 CVE-2014-9112 Upstream summary: USN-5064-1 fixed a vulnerability in GNU. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: […]

Read more
CHAT