Debian 11

Debian 11 — libkf5ksieve — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libkf5ksieve — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-52723 Upstream summary: In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value. Table of […]

Read more
Debian 11 — djangorestframework — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — djangorestframework — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-25045 CVE-2020-25626 CVE-2024-21520 Upstream summary: Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view templates disable autoescaping. Table of contents Symptom […]

Read more
Debian 11 — pure-ftpd — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pure-ftpd — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0656 CVE-2011-0418 CVE-2011-1575 CVE-2019-20176 CVE-2020-9274 CVE-2020-9365 CVE-2021-40524 CVE-2024-48208 Upstream summary: The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by […]

Read more
Debian 11 — gstreamer1.0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gstreamer1.0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5838 CVE-2024-47606 Upstream summary: The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed […]

Read more
Debian 11 — python-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-17626 CVE-2019-19450 CVE-2020-28463 CVE-2023-33733 Upstream summary: ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' […]

Read more
Debian 11 — stellarium — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — stellarium — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-28371 Upstream summary: In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. Table of […]

Read more
Debian 11 — golang-google-protobuf — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-google-protobuf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-24786 Upstream summary: The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which […]

Read more
Debian 11 — llvm-toolchain-16 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — llvm-toolchain-16 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-31852 CVE-2024-7883 Upstream summary: LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can […]

Read more
Debian 11 — janino — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — janino — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 March 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-33546 Upstream summary: Janino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method. If the parser runs on […]

Read more
Debian 11 — python-webob — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-webob — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 February 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-42353 Upstream summary: WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing […]

Read more
CHAT