Package Management

FreeBSD 12 — libjpeg-turbo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libjpeg-turbo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libjpeg-turbo — Issue in the PPM reader causing a buffer overrun in cjpeg, TJBench, or the tjLoadImage() function. Related CVEs: CVE-2012-2806 CVE-2020-13790 Upstream summary: libjpeg-turbo releases reports: This release fixes […]

Read more
FreeBSD 12 — py-django — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py-django — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — CSRF protection bypass on a site with Google Analytics Related CVEs: CVE-2016-7401 Upstream summary: Django Software Foundation reports: An interaction between Google Analytics and Django's cookie parsing could […]

Read more
How to Configure Tekton CI/CD on FreeBSD 12 — step-by-step FreeBSD 12 tutorial on Progressive Robot

How to Configure Tekton CI/CD on FreeBSD 12

Introduction Deploying configure tekton ci/cd on freebsd 12 on a FreeBSD 12 machine differs from Linux in several important ways: packages come from the FreeBSD Ports Collection or the binary pkg repository, services are registered in /etc/rc.conf via sysrc(8), and firewall rules are written in pf.conf(5) syntax. This tutorial stays entirely within the standard base […]

Read more
Ubuntu 16.04 — gthumb — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — gthumb — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 March 2020 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5681-1 Related CVEs: CVE-2018-18718 CVE-2019-20326 CVE-2020-36427 Upstream summary: It was discovered that gThumb did not properly managed memory under certain circumstances. An attacker could possibly use this issue to cause […]

Read more
How to Configure Nginx as a TCP/UDP Load Balancer on Debian 10 — step-by-step Debian 10 tutorial on Progressive Robot

How to Configure Nginx as a TCP/UDP Load Balancer on Debian 10 (DEBIAN-10-2)

Introduction Deploying configure nginx as a tcp/udp load balancer on debian 10 on a Debian 10 Buster machine is straightforward thanks to Debian’s policy-compliant packaging. Unlike rpm-based distributions, Debian stores configuration helpers in /etc/default/, uses update-rc.d for older init scripts, and provides dpkg-reconfigure for interactive package configuration. This tutorial stays on the systemd path throughout. […]

Read more
Oracle Linux 8 — thunderbird — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — thunderbird — vulnerability — patch and remediation guide (ELSA-2020-1495)

🟠 High   ⏱ 15–60 min  Last verified: 21 March 2020 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2020-1495 Related CVEs: CVE-2020-6821 CVE-2020-6822 CVE-2020-6820 CVE-2020-6825 CVE-2020-6819 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative […]

Read more
FreeBSD 12 — go — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — go — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: go — excessive resource consumption Related CVEs: CVE-2015-5739 CVE-2015-5740 CVE-2015-5741 CVE-2015-8618 CVE-2016-3959 CVE-2019-16276 CVE-2020-16845 CVE-2020-24553  +12 more Upstream summary: The Go project reports: Within HostnameError.Error(), when constructing an error string, […]

Read more
FreeBSD 12 — serendipity-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — serendipity-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: serendipity — multiple cross site scripting vulnerabilities Related CVEs: CVE-2008-1385 CVE-2008-1386 Upstream summary: Hanno Boeck reports: The installer of serendipity 1.3 has various Cross Site Scripting issues. This is considered […]

Read more
FreeBSD 12 — abiword — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — abiword — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: abiword, koffice — stack based buffer overflow vulnerabilities Related CVEs: CAN-2005-2972 Upstream summary: Chris Evans reports that AbiWord is vulnerable to multiple stack-based buffer overflow vulnerabilities. This is caused by […]

Read more
CHAT