Debian 12 Bookworm

Debian 12 — fwbuilder — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — fwbuilder — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4956 CVE-2009-4664 Upstream summary: fwb_install in fwbuilder 2.1.19 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/ssh-agent.##### temporary file. Table of contents Symptom […]

Read more
Debian 12 — waagent — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — waagent — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-0804 Upstream summary: An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'. Table of […]

Read more
Debian 12 — perl — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — perl — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-0703 CVE-2002-1323 CVE-2003-0615 CVE-2003-0618 CVE-2003-0900 CVE-2004-0452 CVE-2004-0976 CVE-2005-0155  +12 more Upstream summary: An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for […]

Read more
Debian 12 — libjs-bootbox — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libjs-bootbox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-46998 Upstream summary: Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), […]

Read more
Debian 12 — cryptojs — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — cryptojs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-46233 Upstream summary: crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at […]

Read more
Debian 12 — lua-cgi — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lua-cgi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-2875 Upstream summary: The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers […]

Read more
Debian 12 — libzen — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libzen — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-36646 Upstream summary: A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/Ztring.cpp. The manipulation […]

Read more
Debian 12 — node-ua-parser-js — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-ua-parser-js — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7793 CVE-2021-27292 CVE-2022-25927 Upstream summary: The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). […]

Read more
Debian 12 — jupyter-core — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jupyter-core — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-39286 Upstream summary: Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability […]

Read more
Debian 12 — openimageio — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — openimageio — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-36354 CVE-2022-38143 CVE-2022-41639 CVE-2022-41649 CVE-2022-41684 CVE-2022-41794 CVE-2022-41837 CVE-2022-41838  +12 more Upstream summary: A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. […]

Read more
CHAT