Debian 12 Bookworm

Debian 12 — python-marshmallow — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-marshmallow — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-17175 CVE-2025-68480 Upstream summary: In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" […]

Read more
Debian 12 — iptraf-ng — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — iptraf-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-52949 Upstream summary: iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow […]

Read more
Debian 12 — easy-rsa — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — easy-rsa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-13454 Upstream summary: Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL […]

Read more
Debian 12 — libcrypt-cbc-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libcrypt-cbc-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-0898 CVE-2025-2814 Upstream summary: Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption […]

Read more
Debian 12 — golang-github-lucas-clemente-quic-go — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — golang-github-lucas-clemente-quic-go — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-30591 CVE-2023-49295 CVE-2024-22189 CVE-2024-53259 CVE-2025-29785 CVE-2025-59530 CVE-2025-64702 Upstream summary: quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in […]

Read more
Debian 12 — restrictedpython — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — restrictedpython — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-37271 CVE-2023-41039 CVE-2024-47532 Upstream summary: RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into […]

Read more
Debian 12 — leaflet — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — leaflet — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2025-69993 Upstream summary: Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML […]

Read more
Debian 12 — r-cran-gh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — r-cran-gh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2025-54956 Upstream summary: The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request. […]

Read more
Debian 12 — golang-github-antonmedv-expr — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — golang-github-antonmedv-expr — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2025-29786 Upstream summary: Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, […]

Read more
Debian 12 — libcatalyst-plugin-session-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libcatalyst-plugin-session-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 April 2025 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-25052 CVE-2025-40924 Upstream summary: A vulnerability has been found in Catalyst-Plugin-Session up to 0.40 and classified as problematic. This vulnerability affects the function _load_sessionid of the file lib/Catalyst/Plugin/Session.pm […]

Read more
CHAT