Debian

Debian 12 — php-htmlpurifier — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — php-htmlpurifier — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-2479 CVE-2010-4183 Upstream summary: Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote […]

Read more
Debian 11 — tinyxml2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — tinyxml2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 September 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-11210 CVE-2024-50614 CVE-2024-50615 Upstream summary: TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow […]

Read more
Debian 12 — libgetdata — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libgetdata — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-20204 Upstream summary: A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity […]

Read more
Debian 12 — snmptt — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — snmptt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-24361 Upstream summary: SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Debian 12 — jackd2 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jackd2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-13351 Upstream summary: posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed […]

Read more
Debian 12 — libdata-uuid-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libdata-uuid-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-4184 Upstream summary: Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
Debian 12 — ctn — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ctn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5146 Upstream summary: add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file. Table of contents Symptom & […]

Read more
Debian 12 — chafa — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — chafa — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-1507 CVE-2022-2061 CVE-2022-2301 Upstream summary: chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. […]

Read more
Debian 12 — mistral — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mistral — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-16848 CVE-2018-16849 CVE-2019-3866 Upstream summary: A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow […]

Read more
Debian 12 — ncftp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ncftp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1948 Upstream summary: NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local […]

Read more
CHAT