Debian 11

Debian 11 — openpyxl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — openpyxl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5992 Upstream summary: Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document. Table of contents Symptom & […]

Read more
Debian 11 — software-properties — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — software-properties — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-4407 CVE-2012-0955 CVE-2013-1061 CVE-2020-15709 Upstream summary: ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) […]

Read more
Debian 11 — changetrack — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — changetrack — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3233 Upstream summary: changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by […]

Read more
Debian 11 — libapache2-mod-auth-openid — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libapache2-mod-auth-openid — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-2760 Upstream summary: mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids. Table of contents Symptom & Impact Environment […]

Read more
Debian 11 — python-markdown2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-markdown2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-11888 CVE-2021-26813 Upstream summary: python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- […]

Read more
Debian 11 — eyed3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — eyed3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-1934 Upstream summary: tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary […]

Read more
Debian 11 — qtbase-opensource-src — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — qtbase-opensource-src — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-4549 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 CVE-2015-9541 CVE-2016-10040 CVE-2018-15518  +12 more Upstream summary: QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) […]

Read more
Debian 11 — ruby-actionpack-page-caching — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-actionpack-page-caching — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8159 Upstream summary: There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote […]

Read more
Debian 11 — chocolate-doom — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — chocolate-doom — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-14983 Upstream summary: The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can […]

Read more
Debian 11 — bsdmainutils — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — bsdmainutils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0793 Upstream summary: The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary […]

Read more
CHAT