Debian

Debian 12 — rust-pleaser — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rust-pleaser — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-31153 CVE-2021-31154 CVE-2021-31155 CVE-2023-46277 Upstream summary: please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via […]

Read more
Debian 12 — php-horde-text-filter — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — php-horde-text-filter — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5303 CVE-2021-26929 Upstream summary: Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to […]

Read more
Debian 12 — parallel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — parallel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-4155 CVE-2015-4156 Upstream summary: GNU Parallel before 20150422, when using (1) –pipe, (2) –tmux, (3) –cat, (4) –fifo, or (5) –compress, allows local users to write to arbitrary […]

Read more
Debian 12 — sudo — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — sudo — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1051 CVE-2004-1689 CVE-2005-1119 CVE-2005-1993 CVE-2005-2959 CVE-2005-4158 CVE-2005-4890 CVE-2006-0151  +12 more Upstream summary: sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables […]

Read more
Debian 12 — golang-github-microcosm-cc-bluemonday — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — golang-github-microcosm-cc-bluemonday — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-42576 Upstream summary: The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and […]

Read more
Debian 12 — dpkg-cross — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — dpkg-cross — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4950 Upstream summary: gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the vendor disputes this […]

Read more
Debian 12 — python-keystoneclient — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-keystoneclient — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-2013 CVE-2013-2104 CVE-2013-2166 CVE-2013-2167 CVE-2014-0105 CVE-2014-7144 CVE-2015-1852 Upstream summary: The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the –password argument, which allows local users […]

Read more
Debian 12 — node-opencv — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-opencv — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-10061 Upstream summary: utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to […]

Read more
Debian 12 — nvidia-cg-toolkit — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — nvidia-cg-toolkit — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5144 Upstream summary: nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvidia-cg-toolkit-manifest temporary file. Table of contents Symptom & […]

Read more
Debian 12 — node-dot-prop — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — node-dot-prop — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8116 Upstream summary: Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language […]

Read more
CHAT