Debian

Debian 11 — id3lib3.8.3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — id3lib3.8.3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-4460 Upstream summary: The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file […]

Read more
Debian 11 — ruby-doorkeeper-openid-connect — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-doorkeeper-openid-connect — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-9837 Upstream summary: Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization […]

Read more
Debian 11 — ltris — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ltris — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-0825 Upstream summary: Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file. Table of contents Symptom & Impact Environment […]

Read more
Debian 11 — ruby-kramdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-kramdown — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-14001 CVE-2021-28834 Upstream summary: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") […]

Read more
Debian 11 — kdeplasma-addons — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kdeplasma-addons — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-2120 Upstream summary: The %{password(…)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass […]

Read more
Debian 11 — txt2man — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — txt2man — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-1444 Upstream summary: A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink […]

Read more
Debian 11 — tcpslice — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — tcpslice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-41043 Upstream summary: Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
Debian 11 — hyperkitty — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — hyperkitty — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-33038 Upstream summary: An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, these archives are publicly visible for the duration […]

Read more
Debian 11 — uimaj — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — uimaj — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15691 Upstream summary: In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior […]

Read more
Debian 11 — puppet-module-puppetlabs-apt — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — puppet-module-puppetlabs-apt — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 July 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-6508 CVE-2022-3275 Upstream summary: Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or […]

Read more
CHAT