Debian

Debian 10 — squid — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — squid — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 June 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-12519 CVE-2019-12525 CVE-2019-18860 CVE-2020-15810 CVE-2020-25097 CVE-2021-28116 CVE-2021-28651 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution […]

Read more
Debian 11 — perdition — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — perdition — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-5740 CVE-2013-4584 Upstream summary: The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an […]

Read more
Debian 11 — mailfilter — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mailfilter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-1558 Upstream summary: The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and […]

Read more
Debian 11 — recutils — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — recutils — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-11637 CVE-2019-11638 CVE-2019-11639 CVE-2019-11640 CVE-2019-6455 CVE-2019-6456 CVE-2019-6457 CVE-2019-6458  +6 more Upstream summary: An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the […]

Read more
Debian 11 — ruby-bson — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-bson — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-4410 Upstream summary: The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting […]

Read more
Debian 10 — openldap — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — openldap — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 May 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-12243 CVE-2020-25692 CVE-2020-25709 CVE-2020-36221 CVE-2021-27212 CVE-2022-29155 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
Debian 11 — ruby-websocket-extensions — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-websocket-extensions — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7663 Upstream summary: websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header […]

Read more
Debian 10 — rsyslog — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — rsyslog — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-24903 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 11 — ruby-gon — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-gon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-25739 Upstream summary: An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS […]

Read more
Debian 11 — python-tablib — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-tablib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-2810 Upstream summary: An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. […]

Read more
CHAT