Debian 12 Bookworm

Debian 12 — unrar-free — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — unrar-free — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-11189 CVE-2017-11190 CVE-2017-14120 CVE-2017-14121 CVE-2017-14122 Upstream summary: unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which […]

Read more
Debian 12 — wml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — wml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-0665 CVE-2008-0666 Upstream summary: wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file. Table […]

Read more
Debian 12 — xastir — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xastir — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4987 Upstream summary: xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/ldconfig.tmp, (b) /tmp/ldconf.tmp, and (c) /tmp/ld.so.conf temporary files, related […]

Read more
Debian 12 — rust-arc-swap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rust-arc-swap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-35711 Upstream summary: An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access::Map with the Constant test helper […]

Read more
Debian 12 — python-os-vif — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-os-vif — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-15753 Upstream summary: In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of […]

Read more
Debian 12 — ntirpc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ntirpc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-8779 Upstream summary: rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation […]

Read more
Debian 12 — trafficserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — trafficserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-0256 CVE-2014-10022 CVE-2014-3525 CVE-2014-3624 CVE-2015-3249 CVE-2015-5168 CVE-2015-5206 CVE-2016-5396  +12 more Upstream summary: Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate […]

Read more
Common Problems 120118

Debian 12: High CPU from runaway cron task

🟡 Medium   ⏱ 5–30 min  Last verified: 30 July 2024 Affected versions: Debian 12 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
Debian 12 — golang-golang-x-text — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — golang-golang-x-text — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-14040 CVE-2020-28851 CVE-2020-28852 CVE-2021-38561 CVE-2022-32149 Upstream summary: The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an […]

Read more
Debian 12 — etherape — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — etherape — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-3369 Upstream summary: The add_conversation function in conversations.c in EtherApe before 0.9.12 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via […]

Read more
CHAT