Debian

Debian 12 — scapy — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — scapy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 May 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-1010142 Upstream summary: scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector […]

Read more
Debian 11 — node-babel7 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-babel7 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 May 2024 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-45133 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 12 — json-c — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — json-c — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6370 CVE-2013-6371 CVE-2020-12762 CVE-2021-32292 Upstream summary: Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors. […]

Read more
Debian 12 — isync — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — isync — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-0289 CVE-2021-20247 CVE-2021-3578 CVE-2021-3657 CVE-2021-44143 Upstream summary: Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) […]

Read more
Debian 12 — system-config-printer — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — system-config-printer — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-4405 Upstream summary: The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries […]

Read more
Debian 12 — libdata-formvalidator-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libdata-formvalidator-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-2201 Upstream summary: The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote […]

Read more
Debian 12 — system-tools-backends — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — system-tools-backends — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-6792 Upstream summary: system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective […]

Read more
Debian 12 — openntpd — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — openntpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5117 Upstream summary: OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp […]

Read more
Debian 12 — shadowsocks-libev — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — shadowsocks-libev — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15924 CVE-2019-5152 CVE-2019-5163 CVE-2019-5164 Upstream summary: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via […]

Read more
Debian 12 — diffoscope — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — diffoscope — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0359 CVE-2024-25711 Upstream summary: diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. Table of contents Symptom & Impact Environment […]

Read more
CHAT