Package Management

FreeBSD 13 — py310-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
FreeBSD 13 — finch — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — finch — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pidgin — MSN overflow parsing SLP messages Related CVEs: CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 CVE-2009-1376 CVE-2009-2694 Upstream summary: Secunia reports: A vulnerability has been reported in Pidgin, which can be exploited by […]

Read more
How to Perform a CIS Benchmark Audit on SLES 12 — step-by-step SUSE Linux Enterprise 12 tutorial on Progressive Robot

How to Perform a CIS Benchmark Audit on SLES 12

Introduction This tutorial covers How to Perform a CIS Benchmark Audit on SLES 12 on SLES 12. SLES 12 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 12 system is up to date: […]

Read more
FreeBSD 13 — linux-c7-libsamplerate — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-libsamplerate — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsamplerate — multiple vulnerabilities Related CVEs: CVE-2017-7697 Upstream summary: NVD reports: In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file. […]

Read more
Common Problems 117906

Ubuntu 18.04 LTS – apt update fails with Release file not valid yet – Fix & Prevention

🟠 High   ⏱ 5–30 min  Last verified: 19 June 2021 Affected versions: Ubuntu 18.04 LTS 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors […]

Read more
FreeBSD 13 — pivot-weblog — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pivot-weblog — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pivot-weblog — file deletion vulnerability Upstream summary: Secunia reports: A vulnerability has been discovered in Pivot, which can be exploited by malicious people to delete certain files. Input passed to […]

Read more
FreeBSD 13 — lshell — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lshell — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lshell — Shell autocomplete reveals forbidden directories Upstream summary: lshell reports: The autocomplete feature allows users to list directories, while they do not have access to those paths (issue #109). […]

Read more
Debian 10 — x11vnc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — x11vnc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 June 2021 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-29074 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
How to Install Cassandra on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Install Cassandra on FreeBSD 13

Introduction How to Install Cassandra on FreeBSD 13 is a core administration task for any FreeBSD 13 server operator. FreeBSD 13 ships with the 15.0-RELEASE kernel, ZFS as the default root filesystem, Capsicum capability sandboxing improvements, and an updated ports tree. Unlike Linux distributions, FreeBSD uses rc(8) for service management, pf for packet filtering, and […]

Read more
Ubuntu 20.04 — ring — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — ring — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 June 2021 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6422-1 Related CVEs: CVE-2021-37706 CVE-2021-43299 CVE-2021-43300 CVE-2021-43301 CVE-2021-43302 CVE-2021-43303 CVE-2021-43804 CVE-2021-43845  +12 more Upstream summary: It was discovered that Ring incorrectly handled certain inputs. If a user or an automated […]

Read more
CHAT