Debian

Debian 12 — libtool — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libtool — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-0256 CVE-2009-3736 Upstream summary: GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp. Table […]

Read more
Debian 12 — python-rsa — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-rsa — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-1494 CVE-2020-13757 CVE-2020-25658 Upstream summary: The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via […]

Read more
Debian 12 — fuzz — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — fuzz — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0261 Upstream summary: fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges. Table of contents Symptom & Impact Environment & […]

Read more
Debian 12 — lhasa — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lhasa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-2347 Upstream summary: Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary code via a crafted archive. Table of […]

Read more
Debian 12 — chasquid — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — chasquid — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-52354 Upstream summary: chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
Debian 12 — python-pam — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-pam — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-1502 Upstream summary: Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or […]

Read more
Debian 12 — guake — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — guake — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-23556 Upstream summary: The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus […]

Read more
Debian 12 — rust-libflate — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rust-libflate — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-15552 Upstream summary: An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution. Table of contents Symptom […]

Read more
Debian 12 — cargo — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — cargo — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-10128 CVE-2016-10129 CVE-2016-10130 CVE-2016-8568 CVE-2016-8569 CVE-2019-16760 CVE-2022-36113 CVE-2022-36114  +3 more Upstream summary: Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 […]

Read more
Debian 12 — puppetdb — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — puppetdb — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7943 CVE-2021-27019 CVE-2021-27021 Upstream summary: Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. […]

Read more
CHAT