Debian

Debian 12 — libapache-poi-java — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libapache-poi-java — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 March 2026 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-3529 CVE-2014-3574 CVE-2014-9527 CVE-2016-5000 CVE-2017-12626 CVE-2017-5644 CVE-2019-12415 CVE-2025-31672 Upstream summary: The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an […]

Read more
Debian 13 — node-terser — vulnerability — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — node-terser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2026 Affected versions: Debian 13 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-25858 Upstream summary: The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. […]

Read more
Debian 12 — msgpack-java — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — msgpack-java — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2026 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-21452 Upstream summary: MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects […]

Read more
Debian 12 — kissfft — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — kissfft — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2026 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2025-34297 CVE-2026-41445 Upstream summary: KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft […]

Read more
Debian 13 — node-yargs-parser — vulnerability — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — node-yargs-parser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2026 Affected versions: Debian 13 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7608 Upstream summary: yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Debian 12 — libauthen-sasl-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libauthen-sasl-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 March 2026 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2025-40918 Upstream summary: Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the […]

Read more
Debian 13 — libcrypt-passwdmd5-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — libcrypt-passwdmd5-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 March 2026 Affected versions: Debian 13 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2026-6659 Upstream summary: Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. Table of contents Symptom […]

Read more
Debian 13 — libsepol — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — libsepol — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 March 2026 Affected versions: Debian 13 (trixie) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-36084 CVE-2021-36085 CVE-2021-36086 CVE-2021-36087 Upstream summary: The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper). Table of contents Symptom & Impact […]

Read more
Debian 13 — policykit-1 — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — policykit-1 — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 March 2026 Affected versions: Debian 13 (trixie) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-1658 CVE-2011-1485 CVE-2011-4945 CVE-2013-4288 CVE-2015-3218 CVE-2015-3255 CVE-2015-4625 CVE-2016-2568  +8 more Upstream summary: Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to […]

Read more
Debian 13 — opensaml — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 13

Debian 13 — opensaml — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 March 2026 Affected versions: Debian 13 (trixie) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3474 CVE-2009-3475 CVE-2009-3476 CVE-2025-31335 Upstream summary: OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow […]

Read more
CHAT