Debian

Common Problems 120039

Debian 12: Python venv packages missing after deploy

🟡 Medium   ⏱ 5–30 min  Last verified: 31 August 2023 Affected versions: Debian 12 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
Debian 12 — lucene-solr — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lucene-solr — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-6612 CVE-2013-6397 CVE-2013-6407 CVE-2013-6408 CVE-2017-12629 CVE-2017-3163 CVE-2017-3164 CVE-2018-1308  +9 more Upstream summary: The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers […]

Read more
Debian 12 — eyed3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — eyed3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-1934 Upstream summary: tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary […]

Read more
Debian 12 — whois — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — whois — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0709 Upstream summary: Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary […]

Read more
Debian 12 — gnustep-base — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gnustep-base — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-1457 CVE-2010-1620 CVE-2014-2980 Upstream summary: Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, […]

Read more
Debian 12 — jruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-1330 CVE-2011-4838 CVE-2012-5370 CVE-2015-3900 CVE-2017-17742 CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075  +12 more Upstream summary: The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not […]

Read more
Debian 12 — scheme48 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — scheme48 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-4150 Upstream summary: The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp. Table of contents […]

Read more
Debian 11 — gss-ntlmssp — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gss-ntlmssp — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 August 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-25563 CVE-2023-25565 CVE-2023-25567 Upstream summary: GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM […]

Read more
Debian 12 — quota — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — quota — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-3417 Upstream summary: The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which […]

Read more
Debian 12 — lm-sensors — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lm-sensors — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2672 Upstream summary: pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary […]

Read more
CHAT