Debian

Debian 11 — libeconf — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libeconf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-22652 Upstream summary: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via malformed config files. This issue affects […]

Read more
Debian 11 — dhis-tools-dns — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dhis-tools-dns — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-3341 Upstream summary: DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh […]

Read more
Debian 11 — flac — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — flac — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-4619 CVE-2007-6277 CVE-2007-6278 CVE-2007-6279 CVE-2014-8962 CVE-2014-9028 CVE-2017-6888 CVE-2020-0499  +2 more Upstream summary: Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp […]

Read more
Debian 11 — packer — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — packer — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-15869 Upstream summary: An Amazon Web Services (AWS) developer who does not specify the –owners flag when describing images via AWS CLI, and therefore not properly validating source […]

Read more
Debian 11 — vigor — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — vigor — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-2305 Upstream summary: Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 […]

Read more
Debian 11 — engrampa — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — engrampa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-52138 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 11 — in-toto — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — in-toto — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-32076 Upstream summary: in-toto is a framework to protect supply chain integrity. The in-toto configuration is read from various directories and allows users to configure the behavior of […]

Read more
Debian 11 — rake — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rake — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-8130 Upstream summary: There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. […]

Read more
Debian 11 — xapian-core — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — xapian-core — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-0499 Upstream summary: A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). Table of contents Symptom & Impact […]

Read more
Debian 11 — fuse-exfat — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fuse-exfat — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 January 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-8026 CVE-2022-29973 Upstream summary: Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote attackers to cause a denial of service (infinite loop) […]

Read more
CHAT