Debian 12 Bookworm

Debian 12 — libxdmcp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libxdmcp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-2625 Upstream summary: It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could […]

Read more
Debian 12 — ruby-crack — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-crack — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-1800 Upstream summary: The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks […]

Read more
Debian 12 — xwayland — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xwayland — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-4008 CVE-2021-4009 CVE-2021-4010 CVE-2021-4011 CVE-2022-2319 CVE-2022-2320 CVE-2022-3550 CVE-2022-3551  +12 more Upstream summary: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access […]

Read more
Debian 12 — gdnsd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gdnsd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-13952 Upstream summary: The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv6 address […]

Read more
Debian 12 — multipath-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — multipath-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-0115 CVE-2022-41973 CVE-2022-41974 Upstream summary: The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly […]

Read more
Debian 12 — vim — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — vim — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-1377 CVE-2004-1138 CVE-2005-0069 CVE-2005-2368 CVE-2007-2438 CVE-2007-2953 CVE-2008-2712 CVE-2008-3074  +12 more Upstream summary: vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the […]

Read more
Debian 12 — procmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — procmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-3618 CVE-2017-16844 Upstream summary: Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary […]

Read more
Debian 12 — singular — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — singular — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-40299 Upstream summary: In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via […]

Read more
Debian 12 — libexif — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libexif — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-0664 CVE-2006-4168 CVE-2007-2645 CVE-2007-6351 CVE-2007-6352 CVE-2009-3895 CVE-2012-2812 CVE-2012-2813  +12 more Upstream summary: Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the […]

Read more
Debian 12 — python-rtslib-fb — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-rtslib-fb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-14019 Upstream summary: Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved. Table of contents […]

Read more
CHAT