Debian

Debian 11 — ruby-net-ldap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-net-ldap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 December 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-17718 Upstream summary: The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
Debian 11 — fastjar — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fastjar — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-0831 CVE-2010-2322 Upstream summary: Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. […]

Read more
Debian 11 — link-grammar — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — link-grammar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-5395 Upstream summary: Stack-based buffer overflow in the separate_word function in tokenize.c in Link Grammar 4.1b and possibly other versions, as used in AbiWord Link Grammar 4.2.4, allows […]

Read more
Debian 11 — skktools — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — skktools — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-3916 Upstream summary: The main function in skkdic-expr.c in SKK Tools 1.2 allows local users to overwrite or delete arbitrary files via a symlink attack on a skkdic$PID […]

Read more
Debian 11 — libusrsctp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libusrsctp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-20503 CVE-2022-46871 Upstream summary: usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
Debian 11 — libsmi — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libsmi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-2891 Upstream summary: Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented […]

Read more
Debian 11 — android-platform-system-core — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — android-platform-system-core — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-5564 CVE-2014-1909 CVE-2016-0807 CVE-2016-3861 CVE-2016-3890 CVE-2016-6762 CVE-2017-0647 CVE-2017-0841 Upstream summary: android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack […]

Read more
Debian 11 — amule — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — amule — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-2691 CVE-2006-2692 CVE-2009-1440 Upstream summary: Unspecified "information leakage" vulnerabilities in aMuleWeb for AMule before 2.1.2 allow remote attackers to access arbitrary images, including dynamically generated images, via unknown […]

Read more
Debian 11 — icingaweb2 — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — icingaweb2 — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-18246 CVE-2018-18247 CVE-2018-18248 CVE-2018-18249 CVE-2018-18250 CVE-2020-24368 CVE-2021-32746 CVE-2021-32747  +7 more Upstream summary: Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via […]

Read more
Debian 11 — jackson-databind — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — jackson-databind — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 November 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15095 CVE-2017-17485 CVE-2017-7525 CVE-2018-11307 CVE-2018-12022 CVE-2018-12023 CVE-2018-14718 CVE-2018-14719  +12 more Upstream summary: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could […]

Read more
CHAT