Debian 11

Debian 11 — golang-github-blevesearch-bleve — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-blevesearch-bleve — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-31022 Upstream summary: Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods […]

Read more
Debian 11 — python-websockets — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-websockets — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-33880 Upstream summary: The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=…). An attacker […]

Read more
Debian 11 — libjackson-json-java — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libjackson-json-java — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15095 CVE-2017-7525 CVE-2019-10172 Upstream summary: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code […]

Read more
Debian 11 — node-knockout — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-knockout — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-14862 Upstream summary: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its […]

Read more
Debian 11 — scala — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — scala — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15288 Upstream summary: The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local […]

Read more
Debian 11 — avahi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — avahi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-2288 CVE-2006-2289 CVE-2006-5461 CVE-2006-6870 CVE-2007-3372 CVE-2008-5081 CVE-2009-0758 CVE-2010-2244  +12 more Upstream summary: Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via […]

Read more
Debian 11 — kimageformats — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kimageformats — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-36083 Upstream summary: KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
Debian 11 — graphviz — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — graphviz — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-4803 CVE-2008-4555 CVE-2009-3736 CVE-2014-0978 CVE-2014-1235 CVE-2014-1236 CVE-2014-9157 CVE-2018-10196  +3 more Upstream summary: graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary […]

Read more
Debian 11 — slang2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — slang2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-45927 CVE-2023-45929 Upstream summary: S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf(). Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Debian 11 — android-framework-23 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — android-framework-23 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0752 CVE-2017-0822 Upstream summary: A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835. […]

Read more
CHAT