Debian

Debian 11 — sssd — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — sssd — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-0014 CVE-2010-2940 CVE-2010-4341 CVE-2012-3462 CVE-2013-0219 CVE-2013-0220 CVE-2014-0249 CVE-2015-5292  +9 more Upstream summary: System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC […]

Read more
Debian 11 — node-xmlhttprequest — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — node-xmlhttprequest — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-28502 Upstream summary: This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into […]

Read more
Debian 11 — mathjax — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — mathjax — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-1999024 Upstream summary: MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running […]

Read more
Debian 11 — nim — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nim — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15690 CVE-2020-15692 CVE-2020-15693 CVE-2020-15694 CVE-2021-21372 CVE-2021-21373 CVE-2021-21374 CVE-2021-29495  +1 more Upstream summary: In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains […]

Read more
Debian 11 — iproute2 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — iproute2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-20795 Upstream summary: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a […]

Read more
Debian 11 — gif2apng — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gif2apng — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 February 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-45907 CVE-2021-45908 CVE-2021-45909 CVE-2021-45910 CVE-2021-45911 Upstream summary: An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little […]

Read more
Debian 11 — evolution-rss — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — evolution-rss — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-39361 Upstream summary: In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. […]

Read more
Debian 11 — gpgme1.0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gpgme1.0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-1263 CVE-2014-3564 Upstream summary: GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP […]

Read more
Debian 10 — ipython — vulnerability — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — ipython — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 January 2022 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-21699 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Debian 11 — gsoap — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gsoap — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-9765 CVE-2019-7659 CVE-2020-13574 CVE-2020-13575 CVE-2020-13576 CVE-2020-13577 CVE-2020-13578 CVE-2021-21783  +1 more Upstream summary: Integer overflow in the soap_get function in Genivia gSOAP 2.7.x and 2.8.x before 2.8.48, as used […]

Read more
CHAT