Debian

Debian 12 — mcollective — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mcollective — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-0164 CVE-2014-0175 CVE-2014-3248 CVE-2014-3251 CVE-2016-2788 CVE-2017-2292 Upstream summary: openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, […]

Read more
Debian 11 — iwd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — iwd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 September 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-17497 CVE-2020-8689 CVE-2023-52161 CVE-2024-28084 Upstream summary: eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4. Table of contents […]

Read more
Debian 12 — libjs-jquery-file-upload — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libjs-jquery-file-upload — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-9206 Upstream summary: Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
Debian 12 — gtkpod — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gtkpod — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-37231 Upstream summary: A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because of the missing boundary check. Table of contents […]

Read more
Debian 12 — libvterm — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libvterm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-20786 Upstream summary: libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, […]

Read more
Debian 12 — tre — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — tre — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-8859 Upstream summary: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) […]

Read more
Debian 12 — exim4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — exim4 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-1381 CVE-2004-0399 CVE-2004-0400 CVE-2005-0021 CVE-2005-0022 CVE-2010-2023 CVE-2010-2024 CVE-2010-4344  +12 more Upstream summary: Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim […]

Read more
Debian 12 — nvidia-graphics-drivers-tesla — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nvidia-graphics-drivers-tesla — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-34670 CVE-2022-34674 CVE-2022-34675 CVE-2022-34677 CVE-2022-34679 CVE-2022-34680 CVE-2022-34682 CVE-2022-34684  +12 more Upstream summary: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where […]

Read more
Debian 12 — sqlite3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — sqlite3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-7443 CVE-2015-3414 CVE-2015-3415 CVE-2015-3416 CVE-2016-6153 CVE-2017-10989 CVE-2017-13685 CVE-2017-15286  +12 more Upstream summary: Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial […]

Read more
Debian 12 — node-cached-path-relative — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-cached-path-relative — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-16472 CVE-2021-23518 Upstream summary: A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS […]

Read more
CHAT