Debian

Debian 11 — lz4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lz4 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-4611 CVE-2014-4715 CVE-2019-17543 CVE-2021-3520 Upstream summary: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c […]

Read more
Debian 11 — encfs — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — encfs — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-3073 CVE-2010-3074 CVE-2010-3075 CVE-2014-3462 Upstream summary: SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which […]

Read more
Debian 11 — wildmidi — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — wildmidi — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-1000418 CVE-2017-11661 CVE-2017-11662 CVE-2017-11663 CVE-2017-11664 Upstream summary: The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and […]

Read more
Debian 11 — trafficserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — trafficserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-0256 CVE-2014-10022 CVE-2014-3525 CVE-2014-3624 CVE-2015-3249 CVE-2015-5168 CVE-2015-5206 CVE-2016-5396  +12 more Upstream summary: Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate […]

Read more
Debian 11 — gpicview — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gpicview — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-3791 CVE-2008-3904 Upstream summary: src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg […]

Read more
Debian 11 — smartlist — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — smartlist — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-0157 Upstream summary: The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other […]

Read more
Debian 11 — rpm — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — rpm — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2096 CVE-2005-4889 CVE-2006-5466 CVE-2010-2059 CVE-2010-2197 CVE-2010-2198 CVE-2010-2199 CVE-2011-3378  +12 more Upstream summary: zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via […]

Read more
Debian 11 — php-league-flysystem — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — php-league-flysystem — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-32708 Upstream summary: Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific […]

Read more
Debian 11 — arpwatch — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — arpwatch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-2653 Upstream summary: arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root […]

Read more
Debian 11 — libthai — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libthai — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-4012 Upstream summary: Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to […]

Read more
CHAT