Package Management

Ubuntu 20.04 — libgd2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — libgd2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2021 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7112-1 Related CVEs: CVE-2021-40812 CVE-2017-6363 CVE-2021-38115 CVE-2021-40145 Upstream summary: It was discovered that the GD Graphics Library did not perform proper bounds checking while handling BMP and WebP files. If […]

Read more
Arch Linux — kubectl-ingress-nginx — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — kubectl-ingress-nginx — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-202111-7 Related CVEs: CVE-2021-25742 Upstream summary: Type: information disclosure. Status: Fixed. Affected: 0.33.0-2. Fixed in: 1.0.4-1. Group: AVG-2490. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Ubuntu 18.04 — netqmail — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — netqmail — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2021 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4621-1 Related CVEs: CVE-2005-1513 CVE-2005-1514 CVE-2005-1515 CVE-2020-3811 CVE-2020-3812 Upstream summary: It was discovered that netqmail did not properly handle certain input. Both remote and local attackers could use this vulnerability […]

Read more
SLES 15 — dcraw — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dcraw — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2021 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:3392-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14608 CVE-2021-3624 CVE-2018-19566 CVE-2018-19568 CVE-2018-5805 CVE-2018-5806 CVE-2017-13735 CVE-2018-19655  +3 more Upstream summary: In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw […]

Read more
Oracle Linux 8 — thunderbird — security and stability fixes — required update — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — thunderbird — security and stability fixes — required update (ELSA-2019-1799)

🟠 High   ⏱ 15–60 min  Last verified: 6 May 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2019-1799 Related CVEs: CVE-2019-9811 CVE-2019-11713 CVE-2019-11709 CVE-2019-11711 CVE-2019-11730 CVE-2019-11717 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
How to Configure OPcache for PHP on SLES 15 — step-by-step SUSE Linux Enterprise 15 tutorial on Progressive Robot

How to Configure OPcache for PHP on SLES 15

Introduction This tutorial covers How to Configure OPcache for PHP on SLES 15 on SLES 15. SLES 15 (SUSE Linux Enterprise Server 16) is SUSE’s enterprise-grade Linux distribution. It uses the zypper package manager, AppArmor for mandatory access control, and systemctl for service management. Prerequisites Ensure your SLES 15 system is up to date: zypper […]

Read more
FreeBSD 12 — mariadb102-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb102-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 May 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MariaDB — Vulnerability in C API Related CVEs: CVE-2017-15365 CVE-2020-2574 Upstream summary: MariaDB reports: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL […]

Read more
FreeBSD 12 — py35-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py35-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 May 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Django — multiple vulnerabilities Related CVEs: CVE-2016-2048 CVE-2016-2512 CVE-2016-2513 CVE-2016-9013 CVE-2016-9014 CVE-2017-12794 CVE-2017-7233 CVE-2017-7234  +12 more Upstream summary: Django Release notes: CVE-2020-24583: Incorrect permissions on intermediate-level directories on Python 3.7+ […]

Read more
CHAT