Debian 11

Debian 11 — cracklib2 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — cracklib2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-6318 Upstream summary: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges […]

Read more
Debian 11 — commons-text — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — commons-text — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-42889 Upstream summary: Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used […]

Read more
Debian 11 — liboggplay — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — liboggplay — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3378 CVE-2009-3388 Upstream summary: The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon […]

Read more
Debian 11 — libgdiplus — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libgdiplus — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-1526 Upstream summary: Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the […]

Read more
Debian 11 — merkaartor — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — merkaartor — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-4193 Upstream summary: Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file. Table of contents Symptom & […]

Read more
Debian 11 — haskell-cmark-gfm — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — haskell-cmark-gfm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-5238 Upstream summary: The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown […]

Read more
Debian 11 — dillo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dillo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-0012 CVE-2009-2294 Upstream summary: Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a […]

Read more
Debian 11 — emacs-jabber — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — emacs-jabber — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4952 Upstream summary: emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file. Table of contents Symptom & […]

Read more
Debian 11 — libao — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libao — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-11548 Upstream summary: The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file. […]

Read more
Debian 11 — mp3gain — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mp3gain — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0577 CVE-2004-0805 CVE-2004-0991 CVE-2006-1655 CVE-2017-12911 CVE-2017-12912 CVE-2017-14406 CVE-2017-14407  +11 more Upstream summary: mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code […]

Read more
CHAT