Debian

Debian 11 — pywps — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pywps — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-39371 Upstream summary: An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path […]

Read more
Debian 11 — pg-partman — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pg-partman — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-33204 Upstream summary: In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit […]

Read more
Debian 11 — flamethrower — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — flamethrower — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2008-5141 Upstream summary: flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file. Table of contents Symptom & […]

Read more
Debian 11 — postgrey — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — postgrey — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-1127 Upstream summary: Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly […]

Read more
Debian 11 — icecast2 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — icecast2 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1561 CVE-2004-2027 CVE-2005-0837 CVE-2005-0838 CVE-2011-4612 CVE-2014-9018 CVE-2014-9091 CVE-2015-3026  +1 more Upstream summary: Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an […]

Read more
Debian 11 — libice — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-2626 Upstream summary: It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking […]

Read more
Debian 11 — libvc — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libvc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-1356 Upstream summary: Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to execute arbitrary code via a vCard file […]

Read more
Debian 11 — libstaroffice — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libstaroffice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-9432 Upstream summary: Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx. Table of […]

Read more
Debian 11 — lemonldap-ng — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lemonldap-ng — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-6426 CVE-2019-12046 CVE-2019-13031 CVE-2019-15941 CVE-2019-19791 CVE-2020-16093 CVE-2020-24660 CVE-2021-35472  +11 more Upstream summary: LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote […]

Read more
Debian 11 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — apache2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 December 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2001-1534 CVE-2002-0392 CVE-2002-0654 CVE-2002-0661 CVE-2002-0840 CVE-2002-1156 CVE-2002-1592 CVE-2002-1593  +12 more Upstream summary: mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, […]

Read more
CHAT