Debian

Debian 12 — fcitx5 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — fcitx5 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-37311 Upstream summary: Buffer Overflow vulnerability in fcitx5 5.0.8 allows attackers to cause a denial of service via crafted message to the application's listening port. Table of contents […]

Read more
Debian 12 — netkit-rsh — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — netkit-rsh — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-7282 CVE-2019-7283 CVE-2023-38336 Upstream summary: In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . […]

Read more
Debian 12 — python-bcrypt — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-bcrypt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-1895 Upstream summary: The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which […]

Read more
Debian 12 — unp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — unp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-6610 Upstream summary: unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters […]

Read more
Debian 12 — rpki-client — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rpki-client — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-3909 CVE-2021-43172 CVE-2021-43173 Upstream summary: OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. […]

Read more
Debian 12 — ruby-net-ldap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-net-ldap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-17718 Upstream summary: The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Debian 12 — sks — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — sks — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-3207 Upstream summary: Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to […]

Read more
Debian 12 — python-swiftclient — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-swiftclient — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6396 Upstream summary: The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof […]

Read more
Debian 12 — mat2 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — mat2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 January 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-35410 Upstream summary: mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which […]

Read more
CHAT