Debian 12 Bookworm

Debian 12 — python3-typed-ast — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python3-typed-ast — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-19274 CVE-2019-19275 Upstream summary: typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but […]

Read more
Debian 12 — node-node-sass — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-node-sass — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-24025 Upstream summary: Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path. Table of […]

Read more
Debian 12 — ruamel.yaml — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruamel.yaml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-20478 Upstream summary: In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this […]

Read more
Debian 12 — xboard — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xboard — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2552 Upstream summary: Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the […]

Read more
Debian 12 — protobuf-c — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — protobuf-c — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-33070 CVE-2022-48468 Upstream summary: Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial […]

Read more
Debian 12 — leptonlib — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — leptonlib — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-18196 CVE-2018-3836 CVE-2018-7186 CVE-2018-7247 CVE-2018-7440 CVE-2018-7441 CVE-2018-7442 CVE-2020-36277  +5 more Upstream summary: Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, […]

Read more
Debian 12 — libuev — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libuev — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-48620 Upstream summary: uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number. Table of contents Symptom & Impact Environment & […]

Read more
Debian 12 — xml-light — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xml-light — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-3514 Upstream summary: OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial […]

Read more
Debian 12 — thin — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — thin — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3287 Upstream summary: lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to […]

Read more
Debian 12 — rust-socket2 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rust-socket2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-35920 Upstream summary: An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation. Table of contents Symptom […]

Read more
CHAT