Package Management

FreeBSD 13 — py37-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
Oracle Linux 8 — mariadb:10.3 — security and stability fixes — required update — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — mariadb:10.3 — security and stability fixes — required update (ELSA-2022-1556)

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-1556 Related CVEs: CVE-2021-35604 CVE-2021-46662 CVE-2021-46657 CVE-2021-2154 CVE-2021-46666 CVE-2021-46667 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
FreeBSD 13 — konversation — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — konversation — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: konversation — crash in IRC message parsing Related CVEs: CVE-2005-0129 CVE-2005-0130 CVE-2005-0131 CVE-2014-8483 CVE-2017-15923 Upstream summary: KDE reports: Konversation has support for colors in IRC messages. Any malicious user connected […]

Read more
How to Set Up Lynis Security Auditing on Oracle Linux 8 — step-by-step Oracle Linux 8 tutorial on Progressive Robot

How to Set Up Lynis Security Auditing on Oracle Linux 8

Introduction How to Set Up Lynis Security Auditing on Oracle Linux 8 on Oracle Linux 8 provides administrators with a robust, enterprise-ready workflow that integrates cleanly with systemd, SELinux, firewalld, and the modern AppStream module system. In this tutorial we will walk through every step required, from package installation to verification, so that the resulting […]

Read more
FreeBSD 13 — plone — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — plone — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: plone — multiple vulnerabilities Related CVEs: CVE-2006-1711 CVE-2006-4249 CVE-2007-0240 CVE-2007-5741 CVE-2011-0720 Upstream summary: Plone.org reports: Versions Affected: All current Plone versions. Versions Not Affected: None. Nature of vulnerability: Allows creation […]

Read more
FreeBSD 13 — xfce4-panel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — xfce4-panel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xfce — multiple vulnerabilities Related CVEs: CVE-2007-6531 CVE-2007-6532 Upstream summary: Gentoo reports: A remote attacker could entice a user to install a specially crafted "rc" file to execute arbitrary code […]

Read more
FreeBSD 13 — freeamp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — freeamp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zinf — potential buffer overflow playlist support Upstream summary: The audio player Zinf is vulnerable to a buffer-overflow bug in the management of the playlist files. Table of contents Symptom […]

Read more
Debian 10 — smarty3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — smarty3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2021 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-21408 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
openSUSE Tumbleweed — clone-master-clean-up — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — clone-master-clean-up — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3667-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-32000 Upstream summary: A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux […]

Read more
Ubuntu 14.04 — p11-kit — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — p11-kit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2021 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4677-2 Related CVEs: CVE-2020-29361 Upstream summary: USN-4677-1 fixed a vulnerability in p11-kit. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: David Cook discovered that p11-kit […]

Read more
CHAT