Debian

Debian 11 — golang-github-gin-contrib-cors — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-github-gin-contrib-cors — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-25211 Upstream summary: parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is […]

Read more
Debian 11 — im — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — im — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-1395 Upstream summary: Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary […]

Read more
Debian 11 — gmp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gmp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-43618 Upstream summary: GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault […]

Read more
Debian 11 — fdclone — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fdclone — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0596 Upstream summary: FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to […]

Read more
Debian 11 — python3-typed-ast — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python3-typed-ast — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-19274 CVE-2019-19275 Upstream summary: typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but […]

Read more
Debian 11 — beep — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — beep — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-0492 CVE-2018-1000532 Upstream summary: Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. Table of contents Symptom & Impact Environment & […]

Read more
Debian 11 — ace — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ace — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-6311 Upstream summary: generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. Table of contents Symptom & […]

Read more
Debian 11 — pysha3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pysha3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 June 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-37454 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT