Debian

Debian 11 — openipmi — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — openipmi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2024-42934 Upstream summary: OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) […]

Read more
Debian 12 — gitolite3 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gitolite3 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-7203 CVE-2018-16976 CVE-2018-20683 Upstream summary: gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running […]

Read more
Debian 12 — ppp — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ppp — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1002 CVE-2006-2194 CVE-2008-5366 CVE-2008-5367 CVE-2014-3158 CVE-2015-3310 CVE-2018-11574 CVE-2020-8597  +2 more Upstream summary: Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial […]

Read more
Debian 12 — kio — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — kio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-6410 Upstream summary: kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, […]

Read more
Debian 12 — pigz — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — pigz — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-0296 CVE-2015-1191 Upstream summary: Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those […]

Read more
Debian 12 — cookiecutter — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — cookiecutter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-24065 Upstream summary: The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout […]

Read more
Debian 12 — pcs — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — pcs — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-0720 CVE-2016-0721 CVE-2017-2661 CVE-2018-1079 CVE-2018-1086 CVE-2022-1049 CVE-2022-2735 Upstream summary: Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. Table of contents Symptom & Impact […]

Read more
Debian 12 — fai — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — fai — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-6614 Upstream summary: The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose […]

Read more
Debian 12 — python-glance-store — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-glance-store — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-2088 CVE-2024-1141 Upstream summary: A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A […]

Read more
Debian 12 — amd64-microcode — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — amd64-microcode — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 June 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-5715 CVE-2019-9836 CVE-2023-20569 CVE-2023-20584 CVE-2023-20592 CVE-2023-20593 CVE-2023-31315 CVE-2023-31356  +12 more Upstream summary: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information […]

Read more
CHAT