Debian

Debian 12 — cluster-glue — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — cluster-glue — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-2496 Upstream summary: stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack […]

Read more
Debian 12 — postgresql-ocaml — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — postgresql-ocaml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-2943 Upstream summary: The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping […]

Read more
Debian 12 — yubico-piv-tool — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — yubico-piv-tool — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-14779 CVE-2018-14780 CVE-2020-13131 CVE-2020-13132 Upstream summary: A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function […]

Read more
Debian 12 — shadow — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — shadow — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1001 CVE-2005-4890 CVE-2006-1174 CVE-2006-1376 CVE-2006-1844 CVE-2006-3378 CVE-2007-5686 CVE-2008-5394  +11 more Upstream summary: Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows […]

Read more
Debian 12 — rustc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rustc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-20001 CVE-2017-20004 CVE-2018-1000622 CVE-2018-1000657 CVE-2018-1000810 CVE-2018-25008 CVE-2019-1010299 CVE-2020-36317  +12 more Upstream summary: In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is […]

Read more
Debian 12 — python-oslo.middleware — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — python-oslo.middleware — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-2592 Upstream summary: python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error […]

Read more
Debian 12 — glance — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — glance — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-4573 CVE-2012-5482 CVE-2013-0212 CVE-2013-1840 CVE-2013-4354 CVE-2013-4428 CVE-2014-0162 CVE-2014-1948  +12 more Upstream summary: The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users […]

Read more
Debian 12 — simplesamlphp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — simplesamlphp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-4625 CVE-2012-0040 CVE-2012-0908 CVE-2016-3124 CVE-2016-9814 CVE-2016-9955 CVE-2017-12867 CVE-2017-12868  +12 more Upstream summary: simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote […]

Read more
Debian 12 — pdftk-java — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — pdftk-java — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-37819 Upstream summary: PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
Debian 12 — plasma-discover — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — plasma-discover — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-28117 Upstream summary: libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the […]

Read more
CHAT