Linux

Debian 12 — mod-wsgi — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mod-wsgi — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-0240 CVE-2014-0242 CVE-2014-8583 CVE-2022-2255 Upstream summary: The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when […]

Read more
Debian 12 — bwm-ng — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — bwm-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-1341 Upstream summary: An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/options.c. Table of contents Symptom & Impact Environment […]

Read more
Debian 11 — node-ip — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-ip — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-42282 CVE-2024-29415 Upstream summary: The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via […]

Read more
Debian 12 — djangorestframework — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — djangorestframework — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-25045 CVE-2020-25626 CVE-2024-21520 Upstream summary: Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. Table of contents Symptom […]

Read more
Debian 11 — node-body-parser — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-body-parser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-45590 Upstream summary: body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially […]

Read more
Ubuntu 14.04 — requests — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — requests — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2024 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7568-1 Related CVEs: CVE-2024-47081 CVE-2023-32681 CVE-2018-18074 CVE-2015-2296 CVE-2014-1829 CVE-2014-1830 Upstream summary: Dennis Brinkrolf and Tobias Funke discovered that Requests did not correctly handle certain HTTP headers. A remote attacker could […]

Read more
CentOS Stream 9 — python3.12-PyMySQL — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python3.12-PyMySQL — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9193 Related CVEs: CVE-2024-36039 Upstream summary: This package contains a pure-Python MySQL client library. The goal of PyMySQL is to be a drop-in replacement for MySQLdb and work on CPython, PyPy, […]

Read more
SLES 15 — less — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — less — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1534-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-32487 CVE-2022-48624 CVE-2022-46663 CVE-2014-9488 Upstream summary: less through 653 allows OS command execution via a newline character in the name of a file, because quoting […]

Read more
Oracle Linux 8 — libreswan — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — libreswan — vulnerability — patch and remediation guide (ELSA-2024-1998)

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2024 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2024-1998 Related CVEs: CVE-2024-2357 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT