Debian

Debian 11 — nvi — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nvi — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2001-1562 CVE-2015-2305 Upstream summary: Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename. Table of contents Symptom […]

Read more
Debian 10 — exo — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — exo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2023 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-32278 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 11 — okular — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — okular — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-2575 CVE-2018-1000801 CVE-2020-9359 Upstream summary: Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows […]

Read more
Debian 11 — golang-github-gin-gonic-gin — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-gin-gonic-gin — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-28483 CVE-2020-36567 CVE-2023-26125 CVE-2023-29401 Upstream summary: This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by […]

Read more
Debian 11 — courier — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — courier — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-0914 CVE-2002-1311 CVE-2003-0040 CVE-2004-0224 CVE-2004-0591 CVE-2004-0777 CVE-2004-2313 CVE-2005-1308  +7 more Upstream summary: Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) […]

Read more
Debian 11 — apache-directory-api — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — apache-directory-api — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-3250 Upstream summary: Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
Debian 11 — loggerhead — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — loggerhead — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2011-0728 Upstream summary: Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which […]

Read more
Debian 11 — obs-build — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — obs-build — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-14804 Upstream summary: The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target […]

Read more
Debian 11 — pngquant — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pngquant — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5735 Upstream summary: Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers […]

Read more
Debian 11 — rust-cargo — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rust-cargo — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-36113 CVE-2022-36114 CVE-2022-46176 CVE-2023-38497 CVE-2023-40030 Upstream summary: Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in […]

Read more
CHAT