Debian

Debian 12 — rox — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — rox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 June 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-1956 Upstream summary: ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files. Table of contents Symptom & […]

Read more
Debian 11 — lua-http — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lua-http — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 June 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-4540 Upstream summary: Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending […]

Read more
Common Problems 120131

Debian 12 – Apache2 Fails with Address Already in Use – Port Conflict Resolution

🟠 High   ⏱ 5–30 min  Last verified: 23 June 2023 Affected versions: Debian 12 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
Debian 12 — bash — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — bash — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 June 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5374 CVE-2012-3410 CVE-2012-6711 CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2014-7186  +8 more Upstream summary: bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? […]

Read more
Debian 10 — booth — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — booth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 June 2023 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-2553 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 12 — collectd — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — collectd — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 June 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-3736 CVE-2010-4336 CVE-2016-6254 CVE-2017-16820 CVE-2017-7401 Upstream summary: ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly […]

Read more
Debian 12 — google-perftools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — google-perftools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 June 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-4895 CVE-2018-13420 Upstream summary: Multiple integer overflows in TCMalloc (tcmalloc.cc) in gperftools before 0.4 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows […]

Read more
Debian 11 — node-matrix-js-sdk — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-matrix-js-sdk — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 June 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-40823 CVE-2022-36059 CVE-2022-39236 CVE-2022-39249 CVE-2022-39250 CVE-2022-39251 CVE-2023-28427 CVE-2023-29529  +4 more Upstream summary: A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before […]

Read more
Debian 12 — l2tpns — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — l2tpns — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 June 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-5873 Upstream summary: Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial […]

Read more
CHAT