Debian

Debian 12 — lz4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lz4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-4611 CVE-2014-4715 CVE-2019-17543 CVE-2021-3520 Upstream summary: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c […]

Read more
Debian 12 — node-knockout — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-knockout — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-14862 Upstream summary: There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its […]

Read more
Debian 12 — mediaelement — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mediaelement — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-4567 Upstream summary: Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or […]

Read more
Debian 12 — nuget — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nuget — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-29337 Upstream summary: NuGet Client Remote Code Execution Vulnerability Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
Debian 12 — ibm-3270 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ibm-3270 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-5662 Upstream summary: x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the […]

Read more
Debian 12 — r-cran-haven — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — r-cran-haven — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-11364 CVE-2018-11365 CVE-2018-5698 Upstream summary: sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call. Table of contents Symptom & Impact […]

Read more
Debian 12 — mp3splt — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mp3splt — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15185 CVE-2017-5665 CVE-2017-5666 CVE-2017-5851 Upstream summary: plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to […]

Read more
Debian 12 — logwatch — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — logwatch — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-1061 CVE-2011-1018 Upstream summary: The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that […]

Read more
Debian 12 — mpmath — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mpmath — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-29063 Upstream summary: A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called. Table of contents Symptom […]

Read more
Debian 12 — node-chart.js — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-chart.js — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7746 Upstream summary: This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing […]

Read more
CHAT