Debian

Debian 12 — rush — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rush — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6889 Upstream summary: GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the –lint option. Table of contents Symptom & […]

Read more
Debian 12 — weechat — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — weechat — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-0661 CVE-2011-1428 CVE-2012-5534 CVE-2012-5854 CVE-2017-14727 CVE-2017-8073 CVE-2020-8955 CVE-2020-9759  +4 more Upstream summary: Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service […]

Read more
Debian 12 — gnome-settings-daemon — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gnome-settings-daemon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-38394 Upstream summary: Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate […]

Read more
Debian 12 — unbound — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — unbound — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3602 CVE-2009-4008 CVE-2010-0969 CVE-2011-1922 CVE-2011-4528 CVE-2011-4869 CVE-2014-8602 CVE-2017-15105  +12 more Upstream summary: Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to […]

Read more
Debian 12 — libhtml-prototype-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libhtml-prototype-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-2383 CVE-2008-7220 Upstream summary: The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to […]

Read more
Debian 12 — mootools — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mootools — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-32821 Upstream summary: MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial […]

Read more
Debian 11 — pydantic — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pydantic — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-29510 CVE-2024-3772 Upstream summary: Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) […]

Read more
Debian 12 — llvm-toolchain-16 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — llvm-toolchain-16 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-31852 CVE-2024-7883 Upstream summary: LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can […]

Read more
Debian 12 — rzip — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rzip — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-8364 Upstream summary: The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly […]

Read more
Debian 12 — jenkins-json — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jenkins-json — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 October 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-5072 Upstream summary: Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can […]

Read more
CHAT