Debian 12 Bookworm

Debian 12 — aspell — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — aspell — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0548 CVE-2019-17544 CVE-2019-20433 CVE-2019-25051 Upstream summary: Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long […]

Read more
Debian 12 — mksh — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mksh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-1845 Upstream summary: The Korn shell (aka mksh) before R33d on MirOS (aka MirBSD) does not flush the tty's I/O when invoking mksh in a new terminal, which […]

Read more
Debian 12 — libfwsi — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libfwsi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-17263 Upstream summary: In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap-based buffer over-read because rejection of an unsupported size only considers values less than 6, […]

Read more
Debian 12 — camlimages — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — camlimages — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-2295 CVE-2009-2660 CVE-2009-3296 Upstream summary: Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large […]

Read more
Debian 12 — phpldapadmin — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — phpldapadmin — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2654 CVE-2005-2792 CVE-2005-2793 CVE-2006-2016 CVE-2009-4427 CVE-2011-4074 CVE-2011-4075 CVE-2011-4082  +9 more Upstream summary: phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when […]

Read more
Debian 12 — keepalived — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — keepalived — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-1784 CVE-2018-19044 CVE-2018-19045 CVE-2018-19046 CVE-2018-19115 CVE-2021-44225 CVE-2024-41184 Upstream summary: The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, […]

Read more
Debian 12 — ipcalc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ipcalc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-3848 Upstream summary: Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI […]

Read more
Debian 12 — ros-actionlib — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ros-actionlib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-10289 Upstream summary: Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever […]

Read more
Debian 12 — libwebp — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libwebp — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-5127 CVE-2016-9085 CVE-2016-9969 CVE-2018-25009 CVE-2018-25010 CVE-2018-25011 CVE-2018-25012 CVE-2018-25013  +8 more Upstream summary: Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service […]

Read more
Debian 12 — nmap — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nmap — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-4885 CVE-2017-18594 CVE-2018-1000161 CVE-2018-15173 Upstream summary: The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted […]

Read more
CHAT