Debian

Debian 11 — node-fetch — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-fetch — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15168 CVE-2022-0235 Upstream summary: node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was […]

Read more
Debian 11 — psensor — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — psensor — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-10073 Upstream summary: The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver […]

Read more
Debian 11 — ruby-geocoder — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-geocoder — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7981 Upstream summary: sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data. Table of […]

Read more
Debian 11 — impose+ — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — impose+ — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-4960 Upstream summary: impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files. Table of […]

Read more
Debian 11 — libpff — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libpff — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-11723 CVE-2018-20348 CVE-2020-18897 Upstream summary: The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a […]

Read more
Debian 11 — newlib — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — newlib — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-2305 CVE-2019-14871 CVE-2019-14872 CVE-2019-14873 CVE-2019-14874 CVE-2019-14875 CVE-2019-14876 CVE-2019-14877  +3 more Upstream summary: Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 […]

Read more
Debian 11 — dpkg — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dpkg — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2768 CVE-2005-2096 CVE-2010-0396 CVE-2010-1679 CVE-2011-0402 CVE-2014-0471 CVE-2014-3127 CVE-2014-3227  +8 more Upstream summary: dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file […]

Read more
Debian 11 — nacl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nacl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-0565 Upstream summary: NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
Debian 11 — gopher — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gopher — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0805 CVE-2004-0560 CVE-2004-0561 CVE-2005-1853 CVE-2005-2772 Upstream summary: Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) […]

Read more
Debian 11 — salt — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — salt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 March 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-21996 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
CHAT