Debian 11

Debian 11 — libxmltok — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libxmltok — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3560 CVE-2009-3720 CVE-2012-0876 CVE-2012-1147 CVE-2012-1148 CVE-2012-6702 CVE-2013-0340 CVE-2015-1283  +12 more Upstream summary: The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module […]

Read more
Debian 11 — nginx — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nginx — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-2629 CVE-2009-3555 CVE-2009-3896 CVE-2009-3898 CVE-2009-4487 CVE-2011-4315 CVE-2011-4968 CVE-2012-1180  +12 more Upstream summary: Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and […]

Read more
Debian 11 — freexl — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — freexl — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-2753 CVE-2015-2754 CVE-2015-2776 CVE-2017-2923 CVE-2017-2924 CVE-2018-7435 CVE-2018-7436 CVE-2018-7437  +2 more Upstream summary: FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly […]

Read more
Debian 11 — miniupnpc — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — miniupnpc — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-3985 CVE-2015-6031 CVE-2017-1000494 CVE-2017-8798 Upstream summary: The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that […]

Read more
Debian 11 — tt-rss — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — tt-rss — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-1000035 CVE-2017-16896 CVE-2020-25787 CVE-2020-25788 CVE-2020-25789 Upstream summary: Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
Debian 11 — quota — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — quota — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-3417 Upstream summary: The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which […]

Read more
Debian 11 — node-ansi-up — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-ansi-up — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-3377 Upstream summary: The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to […]

Read more
Debian 11 — libtwelvemonkeys-java — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libtwelvemonkeys-java — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-23792 Upstream summary: The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An […]

Read more
Debian 11 — proxytunnel — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — proxytunnel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2440 Upstream summary: Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users. Table of contents […]

Read more
Debian 11 — cgit — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — cgit — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-1899 CVE-2016-1900 CVE-2016-1901 CVE-2018-14912 Upstream summary: CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP […]

Read more
CHAT