Key Updates Across Debian Versions:
1. Debian 8 (Jessie) Extended LTS:
- ELA-1388-1: Twitter Bootstrap 3 security update addressing multiple XSS vulnerabilities.
2. Debian 9 (Stretch) and 10 (Buster) Extended LTS:
- ELA-1389-1: Twitter Bootstrap 3 security update.
- ELA-1387-1: Erlang security update addressing various vulnerabilities in the Erlang/OTP libraries.
3. Debian 11 (Bullseye) LTS:
- DLA 4125-1: Twitter Bootstrap 4 security update fixing an XSS vulnerability in the carousel component.
- DLA 4127-1: Subversion security update resolving a denial-of-service issue.
- DLA 4126-1: Jinja2 security update addressing vulnerabilities that could allow arbitrary code execution.
- DLA 4124-1: Additional security update for Twitter Bootstrap 3.
4. Debian 12 (Bookworm):
- DSA 5901-1: MediaWiki security update fixing multiple vulnerabilities related to information disclosure and scripting attacks.
- DSA 5902-1: Perl security update addressing a heap-based buffer overflow vulnerability.
Vulnerabilities Addressed:
- Twitter Bootstrap: Multiple versions were affected by XSS vulnerabilities, requiring updates for both Bootstrap 3 and 4.
- MediaWiki: Fixed several vulnerabilities that could lead to information disclosure and cross-site scripting.
- Subversion: Addressed denial-of-service vulnerabilities in the mod_dav_svn module.
- Jinja2: Resolved vulnerabilities that could allow attackers to execute arbitrary Python code through uncontrolled templates.
- Perl: Fixed a critical buffer overflow vulnerability that could lead to denial of service or arbitrary code execution.
- Erlang: Multiple vulnerabilities were fixed, including issues with the SSH transport protocol that could lead to serious security downgrades.
Recommendations:
Users of the affected Debian versions are strongly advised to upgrade their packages to mitigate the risks associated with these vulnerabilities. This update process can be facilitated by visiting the relevant Debian security tracker pages for each package.
Further Information:
For detailed guidance on applying these updates and more on Debian's security advisories, users can refer to the Debian wiki and security advisory pages linked within the updates. Keeping systems updated is essential for maintaining security and performance
Bootstrap, Mediawiki, Subversion, and more updates for Debian
Debian GNU/Linux has been updated with multiple security enhancements, including updates for Twitter-bootstrap, mediawiki, subversion, jinja2, perl, and erlang:
Debian GNU/Linux 8 (Jessie) Extended LTS:
ELA-1388-1 twitter-bootstrap3 security update
Debian GNU/Linux 9 (Stretch) and 10 (Buster) Extended LTS:
ELA-1389-1 twitter-bootstrap3 security update
ELA-1387-1 erlang security update
Debian GNU/Linux 11 (Buster) LTS:
[DLA 4125-1] twitter-bootstrap4 security update
[DLA 4127-1] subversion security update
[DLA 4126-1] jinja2 security update
[DLA 4124-1] twitter-bootstrap3 security update
Debian GNU/Linux 12 (Bookworm):
[DSA 5901-1] mediawiki security update
[DSA 5902-1] perl security updateBootstrap, Mediawiki, Subversion, and more updates for Debian @ Linux Compatible