Package Management

FreeBSD 12 — libgcrypt — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libgcrypt — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgcrypt — ECDSA timing attack Related CVEs: CVE-2013-4242 CVE-2015-7511 CVE-2016-6313 CVE-2017-0379 CVE-2017-7526 CVE-2018-0495 CVE-2019-13627 Upstream summary: GnuPG reports: Mitigate an ECDSA timing attack. Table of contents Symptom & Impact Environment […]

Read more
Alpine Linux edge — binutils-cross-embedded — vulnerability — patch and remediation guide — diagnosis and fix on Alpine Linux edge

Alpine Linux edge — binutils-cross-embedded — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Alpine Linux edge / fixed in 2.37-r0 📖 ~4 min read  •  Source: Alpine secdb entry — binutils-cross-embedded 2.37-r0 Related CVEs: CVE-2020-35448 Upstream summary: Alpine community repository for vedge ships binutils-cross-embedded 2.37-r0 which addresses CVE-2020-35448. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — egroupware — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — egroupware — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: egroupware — two vulnerabilities Related CVEs: CVE-2005-1202 CVE-2005-1203 Upstream summary: Egroupware Team report: Nahuel Grisolia from CYBSEC S.A. Security Systems found two security problems in EGroupware: Serious remote command execution […]

Read more
How to Set Up Nginx with PHP-FPM on Debian 10 — step-by-step Debian 10 tutorial on Progressive Robot

How to Set Up Nginx with PHP-FPM on Debian 10

Introduction Debian 10 Buster is built around the ethos of stability and free software. Setting up set up nginx with php-fpm on debian 10 on Buster leverages the same proven Debian packaging system that powers millions of servers worldwide, while benefiting from the latest upstream releases included in the Buster freeze. Follow each step carefully […]

Read more
FreeBSD 12 — amaya — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — amaya — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: amaya — multiple buffer overflow vulnerabilities Related CVEs: CVE-2006-1900 CVE-2008-5282 CVE-2009-0323 Upstream summary: Secunia reports: A boundary error when processing "div" HTML tags can be exploited to cause a stack-based […]

Read more
FreeBSD 12 — typo — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — typo — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typo3 — Missing access check in Extbase Related CVEs: CVE-2007-1081 CVE-2009-0255 CVE-2009-0256 CVE-2009-0257 CVE-2009-0258 CVE-2009-0815 CVE-2009-0816 CVE-2009-3628  +12 more Upstream summary: TYPO3 reports: Extbase request handling fails to implement a […]

Read more
FreeBSD 12 — py39-Elixir — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-Elixir — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-Elixir — weak use of cryptography Related CVEs: CVE-2012-2146 Upstream summary: Red Hat Security Response Team reports: Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector […]

Read more
FreeBSD 12 — gnomevfs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gnomevfs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnomevfs — unsafe URI handling Related CVEs: CVE-2004-0494 Upstream summary: Alexander Larsson reports that some versions of gnome-vfs and MidnightCommander contain a number of `extfs' scripts that do not properly […]

Read more
Arch Linux — packagekit — vulnerability — patch and remediation guide — diagnosis and fix on Arch Linux

Arch Linux — packagekit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: Arch Linux (rolling release) 📖 ~4 min read  •  Source: Arch ASA ASA-202106-18 Related CVEs: CVE-2020-16121 Upstream summary: Type: information disclosure. Status: Fixed. Affected: 1.1.13-1. Fixed in: 1.2.3-1. Group: AVG-1260. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Ubuntu 16.04 — httpcomponents-client — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — httpcomponents-client — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5239-1 Related CVEs: CVE-2020-13956 Upstream summary: It was discovered that HttpClient mishandled certain input. An attacker could use this vulnerability to cause a crash or possibly execute arbitrary code. Table […]

Read more
CHAT