Debian

Debian 11 — nagios-nrpe — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nagios-nrpe — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-1362 CVE-2014-2913 CVE-2020-6581 CVE-2020-6582 Upstream summary: Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands […]

Read more
Debian 11 — php-horde-mime-viewer — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — php-horde-mime-viewer — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-26874 Upstream summary: lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT […]

Read more
Debian 11 — roaraudio — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — roaraudio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-3363 Upstream summary: roarify in roaraudio 0.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library […]

Read more
Debian 11 — python-django-registration — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-django-registration — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-21416 Upstream summary: django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration […]

Read more
Debian 11 — unoconv — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — unoconv — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-17400 Upstream summary: The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
Debian 11 — slim — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — slim — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-1756 CVE-2010-2945 CVE-2013-4412 Upstream summary: SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and […]

Read more
Debian 11 — busybox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — busybox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-1058 CVE-2011-2716 CVE-2011-5325 CVE-2013-1813 CVE-2014-4607 CVE-2014-9645 CVE-2015-9261 CVE-2016-2147  +12 more Upstream summary: BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local […]

Read more
Debian 10 — intel-microcode — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — intel-microcode — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 February 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-11135 CVE-2019-14607 CVE-2020-0543 CVE-2020-24489 CVE-2022-21123 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative […]

Read more
Debian 11 — pcs — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pcs — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-0720 CVE-2016-0721 CVE-2017-2661 CVE-2018-1079 CVE-2018-1086 CVE-2022-1049 CVE-2022-2735 Upstream summary: Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. Table of contents Symptom & Impact […]

Read more
Debian 11 — unicon — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — unicon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-2835 Upstream summary: Multiple stack-based buffer overflows in (1) CCE_pinyin.c and (2) xl_pinyin.c in ImmModules/cce/ in unicon-imc2 3.0.4, as used by zhcon and other applications, allow local users […]

Read more
CHAT