Debian

Debian 11 — xapian-omega — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — xapian-omega — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-2947 Upstream summary: Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which […]

Read more
Debian 11 — libcrypt-openssl-dsa-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libcrypt-openssl-dsa-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-0129 Upstream summary: libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the […]

Read more
Debian 11 — polygen — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — polygen — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2656 Upstream summary: Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform […]

Read more
Debian 11 — vtk7 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — vtk7 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-42521 Upstream summary: There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 […]

Read more
Debian 11 — wims — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — wims — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2006-5443 CVE-2008-4986 Upstream summary: Unspecified vulnerability in XIAO Gang WWW Interactive Mathematics Server (WIMS) before 3.60 allows remote attackers to modify unspecified data via unspecified vectors involving "variable […]

Read more
Debian 11 — umoci — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — umoci — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2021-29136 Upstream summary: Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or […]

Read more
Debian 11 — ruby-kaminari — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-kaminari — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-11082 Upstream summary: In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been […]

Read more
Debian 11 — lm-sensors — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lm-sensors — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2672 Upstream summary: pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary […]

Read more
Debian 11 — abcm2ps — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — abcm2ps — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-1258 CVE-2010-3441 CVE-2010-4743 CVE-2010-4744 CVE-2018-10753 CVE-2018-10771 CVE-2019-1010069 CVE-2021-32434  +2 more Upstream summary: Buffer overflow in the put_words function in subs.c for abcm2ps 3.7.20 allows remote attackers to execute […]

Read more
Debian 11 — jscropperui — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — jscropperui — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 November 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-2383 CVE-2008-7220 Upstream summary: The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to […]

Read more
CHAT