Debian

Debian 12 — ruby-rack-cors — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-rack-cors — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-11173 CVE-2019-18978 Upstream summary: Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to […]

Read more
Debian 12 — libconfig-model-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libconfig-model-perl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0373 CVE-2017-0374 Upstream summary: The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an […]

Read more
Debian 12 — flamethrower — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — flamethrower — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5141 Upstream summary: flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file. Table of contents Symptom & […]

Read more
Debian 12 — xerces-c — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xerces-c — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-1885 CVE-2012-0880 CVE-2015-0252 CVE-2016-0729 CVE-2016-2099 CVE-2016-4463 CVE-2017-12627 CVE-2018-1311  +1 more Upstream summary: Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to […]

Read more
Debian 12 — mathtex — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mathtex — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-1383 CVE-2009-2460 CVE-2009-2461 CVE-2023-51885 CVE-2023-51886 CVE-2023-51887 CVE-2023-51888 CVE-2023-51889  +1 more Upstream summary: The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute […]

Read more
Debian 12 — groovy — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — groovy — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-3253 CVE-2016-6814 CVE-2020-17521 Upstream summary: The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of […]

Read more
Debian 11 — ruby-protocol-http1 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-protocol-http1 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-38697 Upstream summary: protocol-http1 provides a low-level implementation of the HTTP/1 protocol. RFC 9112 Section 7.1 defined the format of chunk size, chunk data and chunk extension. The […]

Read more
Debian 12 — rust-capnp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rust-capnp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-46149 Upstream summary: Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well […]

Read more
Debian 12 — pimd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — pimd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-0007 Upstream summary: pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal […]

Read more
Debian 12 — ruby-actionpack-page-caching — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-actionpack-page-caching — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8159 Upstream summary: There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote […]

Read more
CHAT