Debian

Debian 12 — python-markdown2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-markdown2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-11888 CVE-2021-26813 Upstream summary: python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- […]

Read more
Debian 12 — gnome-maps — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gnome-maps — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-43091 Upstream summary: A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is […]

Read more
Debian 12 — jackson-dataformat-xml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jackson-dataformat-xml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-3720 CVE-2016-7051 Upstream summary: XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown […]

Read more
Debian 12 — libapache2-mod-authnz-external — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libapache2-mod-authnz-external — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-2688 Upstream summary: SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands […]

Read more
Debian 12 — libpoe-component-irc-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libpoe-component-irc-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-3438 Upstream summary: libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such […]

Read more
Debian 12 — postfix — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — postfix — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0468 CVE-2003-0540 CVE-2005-0337 CVE-2008-2936 CVE-2008-2937 CVE-2008-3889 CVE-2009-2939 CVE-2011-0411  +3 more Upstream summary: Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos […]

Read more
Debian 12 — beep — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — beep — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-0492 CVE-2018-1000532 Upstream summary: Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. Table of contents Symptom & Impact Environment & […]

Read more
Debian 12 — ruby-apollo-upload-server — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — ruby-apollo-upload-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-39880 Upstream summary: A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 before 14.0.9, all versions starting from 14.1 […]

Read more
Debian 12 — dist — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — dist — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4949 Upstream summary: dist 3.5 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/cil#####, (b) /tmp/pdo#####, and (c) /tmp/pdn##### temporary files, related to […]

Read more
Common Problems 119961

Debian 12 – NO_PUBKEY and Repository Signature Failures – apt Trust Repair

🟠 High   ⏱ 5–30 min  Last verified: 14 December 2023 Affected versions: Debian 12 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
CHAT