Debian 12 Bookworm

Debian 12 — lam — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lam — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3736 Upstream summary: ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to […]

Read more
Debian 12 — ruby-zip — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-zip — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5946 CVE-2018-1000544 CVE-2019-16892 Upstream summary: The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip […]

Read more
Debian 12 — bash-completion — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — bash-completion — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-7738 Upstream summary: In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount […]

Read more
Debian 12 — libthai — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libthai — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-4012 Upstream summary: Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to […]

Read more
Debian 12 — ruby-redcarpet — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-redcarpet — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-26298 Upstream summary: Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. […]

Read more
Debian 12 — nextcloud-desktop — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nextcloud-desktop — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8189 CVE-2020-8225 CVE-2020-8227 CVE-2021-22879 CVE-2021-22895 CVE-2021-32728 CVE-2022-39331 CVE-2022-39332  +11 more Upstream summary: A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local […]

Read more
Debian 12 — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4551 CVE-2009-0790 CVE-2009-1957 CVE-2009-1958 CVE-2009-2185 CVE-2009-2661 CVE-2010-2628 CVE-2012-2388  +12 more Upstream summary: strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via […]

Read more
Debian 12 — linux — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — linux — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0230 CVE-2005-3660 CVE-2007-3719 CVE-2008-2544 CVE-2008-4609 CVE-2010-4563 CVE-2010-5313 CVE-2010-5321  +12 more Upstream summary: TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence […]

Read more
Debian 12 — node-connect — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-connect — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-7370 CVE-2018-3717 Upstream summary: node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
Debian 12 — lava — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lava — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-12563 CVE-2018-12564 CVE-2018-12565 CVE-2022-42902 CVE-2022-44641 CVE-2022-45132 Upstream summary: An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn […]

Read more
CHAT