Debian 11

Debian 11 — miller — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — miller — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15167 Upstream summary: In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run […]

Read more
Debian 11 — ruby-mixlib-archive — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-mixlib-archive — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-1000026 Upstream summary: Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar […]

Read more
Debian 11 — csound — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — csound — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5986 CVE-2012-0270 CVE-2012-2106 CVE-2012-2107 CVE-2012-2108 Upstream summary: Untrusted search path vulnerability in the (1) "VST plugin with Python scripting" and (2) "VST plugin for writing score generators in […]

Read more
Debian 11 — node-chownr — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-chownr — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-18869 Upstream summary: A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories […]

Read more
Debian 11 — ikiwiki-hosting — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ikiwiki-hosting — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6047 Upstream summary: Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via […]

Read more
Debian 11 — yaws — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — yaws — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2008 CVE-2009-0751 CVE-2009-4495 CVE-2011-4350 CVE-2011-5025 CVE-2016-1000108 CVE-2017-10974 CVE-2020-24379  +1 more Upstream summary: Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts […]

Read more
Debian 11 — simple-xml — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — simple-xml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-1000190 Upstream summary: SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. Table of contents Symptom & Impact Environment […]

Read more
Debian 11 — node-kind-of — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-kind-of — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-20149 Upstream summary: ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, […]

Read more
CHAT