Package Management

FreeBSD 12 — apache-tomcat — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — apache-tomcat — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tomcat — XSS vulnerability in sample applications Related CVEs: CVE-2005-2090 CVE-2007-0450 CVE-2007-1355 CVE-2007-1358 Upstream summary: The Apache Project reports: The JSP and Servlet included in the sample application within the […]

Read more
openSUSE Tumbleweed — aria2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — aria2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2009-3617 CVE-2019-3500 Upstream summary: Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to […]

Read more
Ubuntu 18.04 — wavpack — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — wavpack — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2020 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4682-1 Related CVEs: CVE-2020-35738 CVE-2019-1010315 CVE-2019-1010317 CVE-2019-1010318 CVE-2019-1010319 CVE-2019-11498 CVE-2018-19840 CVE-2018-19841  +5 more Upstream summary: It was discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use […]

Read more
Ubuntu 18.04 — opendmarc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — opendmarc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 April 2020 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6356-1 Related CVEs: CVE-2020-12272 CVE-2020-12460 CVE-2019-16378 Upstream summary: Jianjun Chen, Vern Paxson and Jian Jiang discovered that OpenDMARC incorrectly handled certain inputs. If a user or an automated system were […]

Read more
Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide (ELSA-2020-5756)

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2020 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2020-5756 Related CVEs: CVE-2020-0543 CVE-2020-10757 CVE-2020-10711 CVE-2020-12655 CVE-2020-12770 CVE-2019-19769 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
Arch Linux — coturn — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — coturn — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-202101-21 Related CVEs: CVE-2020-26262 Upstream summary: Type: insufficient validation. Status: Fixed. Affected: 4.5.1.3-2. Fixed in: 4.5.2-1. Group: AVG-1430. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
How to Manage Users and Groups on Debian 10 — step-by-step Debian 10 tutorial on Progressive Robot

How to Manage Users and Groups on Debian 10

Introduction How to Manage Users and Groups on Debian 10 is a fundamental operation for any administrator maintaining a Debian 10 Buster server. Debian 10 Buster ships with the Linux 6.12 kernel, updated toolchains, and a fully refreshed package archive — meaning version numbers, configuration file paths, and some dependency chains differ from Debian 10. […]

Read more
Oracle Linux 8 — fribidi — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — fribidi — vulnerability — patch and remediation guide (ELSA-2019-4361)

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2020 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2019-4361 Related CVEs: CVE-2019-18397 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Oracle Linux 8 — freeradius:3.0 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — freeradius:3.0 — vulnerability — patch and remediation guide (ELSA-2019-1142)

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2020 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2019-1142 Related CVEs: CVE-2019-11235 CVE-2019-11234 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
Arch Linux — libsoup — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — libsoup — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-201708-5 Related CVEs: CVE-2017-2885 Upstream summary: Type: arbitrary code execution. Status: Fixed. Affected: 2.58.1-1. Fixed in: 2.58.2-1. Group: AVG-376. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
CHAT