Debian 11

Debian 11 — elvish — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — elvish — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-41088 Upstream summary: Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) […]

Read more
Debian 11 — ruby-apollo-upload-server — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-apollo-upload-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-39880 Upstream summary: A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 […]

Read more
Debian 11 — pads — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pads — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2269 Upstream summary: Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name […]

Read more
Debian 11 — python-pykmip — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-pykmip — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-1000872 Upstream summary: OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result […]

Read more
Debian 11 — node-fresh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-fresh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-16119 Upstream summary: Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when […]

Read more
Debian 11 — vcftools — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — vcftools — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-11099 CVE-2018-11129 CVE-2018-11130 CVE-2019-1010127 Upstream summary: The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted vcf […]

Read more
Debian 11 — network-manager-ssh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — network-manager-ssh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-9355 Upstream summary: danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
Debian 11 — groonga — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — groonga — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-11675 Upstream summary: The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe […]

Read more
Debian 11 — rails — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rails — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-4111 CVE-2006-4112 CVE-2007-3227 CVE-2007-5379 CVE-2007-5380 CVE-2007-6077 CVE-2008-4094 CVE-2008-5189  +12 more Upstream summary: Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" […]

Read more
Debian 11 — golang-github-go-macaron-i18n — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-go-macaron-i18n — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-36627 Upstream summary: A vulnerability was found in Macaron i18n. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file i18n.go. […]

Read more
CHAT