ubuntu

Ubuntu 16.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — logback — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7616-1 Related CVEs: CVE-2023-6378 CVE-2021-42550 Upstream summary: It was discovered that logback could read malicious configuration files from LDAP servers. An attacker with the required permissions could possibly use this […]

Read more
Ubuntu 18.04 — libde265 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — libde265 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 January 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6764-1 Related CVEs: CVE-2023-51792 CVE-2023-27102 CVE-2023-27103 CVE-2023-43887 CVE-2023-47471 CVE-2023-49465 CVE-2023-49467 CVE-2023-49468  +12 more Upstream summary: It was discovered that libde265 could be made to allocate memory that exceeds the maximum […]

Read more
How To Secure Apache with Let's Encrypt on Ubuntu — step-by-step Linux tutorial on Progressive Robot

How To Secure Apache with Let’s Encrypt on Ubuntu

Let’s Encrypt is a Certificate Authority (CA) that facilitates obtaining and installing free TLS/SSL certificates, thereby enabling encrypted HTTPS on web servers. Currently, the entire process of obtaining and installing a certificate is fully automated on both Apache and Nginx with the use of Certbot. In this guide, we’ll use Certbot to obtain a free SSL certificate for Apache on Ubuntu and make sure this certificate is set up to renew automatically.

Read more
Ubuntu 18.04 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 January 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6590-1 Related CVEs: CVE-2018-1311 CVE-2023-37536 CVE-2016-2099 CVE-2016-4463 CVE-2017-12627 Upstream summary: It was discovered that Xerces-C++ was not properly handling memory management operations when parsing XML data containing external DTDs, which […]

Read more
Ubuntu 16.04 — htmlunit — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — htmlunit — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 January 2024 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8220-1 Related CVEs: CVE-2023-49093 CVE-2020-5529 Upstream summary: It was discovered that HtmlUnit was vulnerable to remote code execution via XSLT when browsing an attacker-controlled webpage. An attacker could possibly use […]

Read more
Ubuntu 22.04 — postfixadmin — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — postfixadmin — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 January 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6550-1 Related CVEs: CVE-2022-29221 CVE-2022-31129 CVE-2023-28447 Upstream summary: It was discovered that Smarty, that is integrated in the PostfixAdmin code, was not properly sanitizing user input when generating templates. An […]

Read more
Ubuntu 14.04 — debian-goodies — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — debian-goodies — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 January 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-8109-1 Related CVEs: CVE-2023-27635 Upstream summary: Jakub Wilk discovered that debmany in Debian Goodies incorrectly handled certain deb files. An attacker could possibly use this issue to execute arbitrary shell […]

Read more
Common Problems 117000

Ubuntu 22.04 LTS Cloud-Init Overwrites Manual Network Configuration

🟡 Medium   ⏱ 5–30 min  Last verified: 2 January 2024 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & Cross-Refs References & Further […]

Read more
Common Problems 117065

Ubuntu 22.04 LTS – MySQL login fails after auth plugin mismatch – Fix & Prevention

🟠 High   ⏱ 5–30 min  Last verified: 1 January 2024 Affected versions: Ubuntu 22.04 LTS 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors […]

Read more
Ubuntu 18.04 — sniproxy — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — sniproxy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 January 2024 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6148-1 Related CVEs: CVE-2023-25076 Upstream summary: It was discovered that SNI Proxy did not properly handle wildcard backend hosts. An attacker could possibly use this issue to cause a buffer […]

Read more
CHAT