Debian

Debian 11 — libnl3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libnl3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0553 Upstream summary: An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This […]

Read more
Debian 11 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-5384 Upstream summary: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary […]

Read more
Debian 11 — libpgf — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libpgf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2015-6673 Upstream summary: Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution […]

Read more
Debian 11 — lua-cgi — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — lua-cgi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-2875 Upstream summary: The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers […]

Read more
Debian 11 — php-horde-ingo — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — php-horde-ingo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2013-6275 Upstream summary: Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Debian 11 — nas — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nas — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-1543 CVE-2007-1544 CVE-2007-1545 CVE-2007-1546 CVE-2007-1547 CVE-2013-4256 CVE-2013-4258 Upstream summary: Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows […]

Read more
Debian 11 — libnfsidmap — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — libnfsidmap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-4135 Upstream summary: The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause […]

Read more
Debian 11 — python-engineio — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — python-engineio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2019-13611 Upstream summary: An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a […]

Read more
Debian 11 — pvpgn — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — pvpgn — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2004-2705 CVE-2005-2096 CVE-2008-5370 Upstream summary: Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password […]

Read more
Debian 11 — sane-backends — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — sane-backends — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0773 CVE-2003-0774 CVE-2003-0775 CVE-2003-0776 CVE-2003-0777 CVE-2003-0778 CVE-2017-6318 CVE-2020-12861  +8 more Upstream summary: saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host […]

Read more
CHAT