Debian

Debian 12 — netpbm-free — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — netpbm-free — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0146 CVE-2003-0924 CVE-2005-2471 CVE-2005-2978 CVE-2005-3632 CVE-2005-3662 CVE-2008-0554 CVE-2009-4274  +3 more Upstream summary: Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to […]

Read more
Debian 12 — yara — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — yara — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-10210 CVE-2016-10211 CVE-2017-11328 CVE-2017-5923 CVE-2017-5924 CVE-2017-8294 CVE-2017-8929 CVE-2017-9304  +11 more Upstream summary: libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference […]

Read more
Debian 12 — python-pyrdfa — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-pyrdfa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-4396 Upstream summary: A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to […]

Read more
Debian 12 — sqliteodbc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — sqliteodbc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-12050 Upstream summary: SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a […]

Read more
Debian 12 — pure-ftpd — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — pure-ftpd — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0656 CVE-2011-0418 CVE-2011-1575 CVE-2019-20176 CVE-2020-9274 CVE-2020-9365 CVE-2021-40524 CVE-2024-48208 Upstream summary: The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by […]

Read more
Debian 12 — libtk-img — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libtk-img — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-5137 CVE-2007-5378 CVE-2008-0553 Upstream summary: Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame […]

Read more
Debian 12 — rkhunter — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rkhunter — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-1270 CVE-2008-4982 CVE-2017-7480 Upstream summary: The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users […]

Read more
Debian 12 — cronic — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — cronic — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-3992 Upstream summary: cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file […]

Read more
Debian 12 — ruby-rack-ssl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-rack-ssl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-2538 Upstream summary: Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via […]

Read more
Debian 12 — arpwatch — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — arpwatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-2653 Upstream summary: arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root […]

Read more
CHAT