stdlib 1.24.2 (golang)
pkg:golang/stdlib@1.24.2

Affected range | >=1.24.0-0 <1.24.4
| Fixed version | 1.24.4 | EPSS Score | 0.012% | EPSS Percentile | 1st percentile |
Description
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

Affected range | >=1.24.0-0 <1.24.4
| Fixed version | 1.24.4 | EPSS Score | 0.014% | EPSS Percentile | 2nd percentile |
Description
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Affected range | >=1.24.0 <1.24.6
| Fixed version | 1.24.6 | EPSS Score | 0.017% | EPSS Percentile | 3rd percentile |
Description
If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Affected range | >=1.24.0-0 <1.24.4
| Fixed version | 1.24.4 | EPSS Score | 0.011% | EPSS Percentile | 1st percentile |
Description
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.
|
glibc 2.36-9+deb12u10 (deb)
pkg:deb/debian/glibc@2.36-9%2Bdeb12u10?os_distro=bookworm&os_name=debian&os_version=12

Affected range | <2.36-9+deb12u11 | Fixed version | 2.36-9+deb12u11 | EPSS Score | 0.011% | EPSS Percentile | 1st percentile |
Description
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

Affected range | <2.36-9+deb12u13 | Fixed version | 2.36-9+deb12u13 | EPSS Score | 0.008% | EPSS Percentile | 1st percentile |
Description
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.
|
perl 5.36.0-7+deb12u2 (deb)
pkg:deb/debian/perl@5.36.0-7%2Bdeb12u2?os_distro=bookworm&os_name=debian&os_version=12

Affected range | <5.36.0-7+deb12u3 | Fixed version | 5.36.0-7+deb12u3 | EPSS Score | 0.911% | EPSS Percentile | 75th percentile |
Description
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
[experimental] - perl 5.38.0~rc2-1

Affected range | <5.36.0-7+deb12u3 | Fixed version | 5.36.0-7+deb12u3 | EPSS Score | 0.008% | EPSS Percentile | 0th percentile |
Description
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
[experimental] - perl 5.40.1-4
|
jq 1.6-2.1 (deb)
pkg:deb/debian/jq@1.6-2.1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | <1.6-2.1+deb12u1 | Fixed version | 1.6-2.1+deb12u1 | EPSS Score | 0.130% | EPSS Percentile | 33rd percentile |
Description
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function jv_string_vfmt in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 void* p = malloc(sz); . As of time of publication, no patched versions are available.
|
gnutls28 3.7.9-2+deb12u4 (deb)
pkg:deb/debian/gnutls28@3.7.9-2%2Bdeb12u4?os_distro=bookworm&os_name=debian&os_version=12

Affected range | <3.7.9-2+deb12u5 | Fixed version | 3.7.9-2+deb12u5 | EPSS Score | 0.062% | EPSS Percentile | 20th percentile |
Description
A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Affected range | <3.7.9-2+deb12u5 | Fixed version | 3.7.9-2+deb12u5 | EPSS Score | 0.079% | EPSS Percentile | 24th percentile |
Description
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system.

Affected range | <3.7.9-2+deb12u5 | Fixed version | 3.7.9-2+deb12u5 | EPSS Score | 0.061% | EPSS Percentile | 19th percentile |
Description
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.

Affected range | <3.7.9-2+deb12u5 | Fixed version | 3.7.9-2+deb12u5 | EPSS Score | 0.029% | EPSS Percentile | 7th percentile |
Description
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.
|
tar 1.34+dfsg-1.2+deb12u1 (deb)
pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=1.34+dfsg-1.2+deb12u1 | Fixed version | Not Fixed | EPSS Score | 0.049% | EPSS Percentile | 15th percentile |
Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages).
Disputed tar issue, works as documented per upstream:
https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html
https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md

Affected range | >=1.34+dfsg-1.2+deb12u1 | Fixed version | Not Fixed | EPSS Score | 3.250% | EPSS Percentile | 87th percentile |
Description
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
This is intended behaviour, after all tar is an archiving tool and you
need to give -p as a command line flag
|
krb5 1.20.1-2+deb12u3 (deb)
pkg:deb/debian/krb5@1.20.1-2%2Bdeb12u3?os_distro=bookworm&os_name=debian&os_version=12

Affected range | <1.20.1-2+deb12u4 | Fixed version | 1.20.1-2+deb12u4 | EPSS Score | 0.030% | EPSS Percentile | 7th percentile |
Description
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
|
stdlib 1.23.10 (golang)
pkg:golang/stdlib@1.23.10

Affected range | <1.23.12 | Fixed version | 1.23.12 | EPSS Score | 0.017% | EPSS Percentile | 3rd percentile |
Description
If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.
|
openldap 2.5.13+dfsg-5 (deb)
pkg:deb/debian/openldap@2.5.13%2Bdfsg-5?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=2.5.13+dfsg-5 | Fixed version | Not Fixed | EPSS Score | 0.500% | EPSS Percentile | 65th percentile |
Description
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

Affected range | >=2.5.13+dfsg-5 | Fixed version | Not Fixed | EPSS Score | 2.838% | EPSS Percentile | 86th percentile |
Description
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

Affected range | >=2.5.13+dfsg-5 | Fixed version | Not Fixed | EPSS Score | 0.113% | EPSS Percentile | 31st percentile |
Description
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill cat /pathname " command, as demonstrated by openldap-initscript.

Affected range | >=2.5.13+dfsg-5 | Fixed version | Not Fixed | EPSS Score | 1.757% | EPSS Percentile | 82nd percentile |
Description
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
- openldap (unimportant)
Debian builds with GNUTLS, not NSS
|
libgcrypt20 1.10.1-3 (deb)
pkg:deb/debian/libgcrypt20@1.10.1-3?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=1.10.1-3 | Fixed version | Not Fixed | EPSS Score | 0.259% | EPSS Percentile | 49th percentile |
Description
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Affected range | >=1.10.1-3 | Fixed version | Not Fixed | EPSS Score | 0.549% | EPSS Percentile | 67th percentile |
Description
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
|
coreutils 9.1-1 (deb)
pkg:deb/debian/coreutils@9.1-1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=9.1-1 | Fixed version | Not Fixed | EPSS Score | 0.018% | EPSS Percentile | 3rd percentile |
Description
A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Affected range | >=9.1-1 | Fixed version | Not Fixed | EPSS Score | 0.056% | EPSS Percentile | 17th percentile |
Description
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
|
apt 2.6.1 (deb)
pkg:deb/debian/apt@2.6.1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=2.6.1 | Fixed version | Not Fixed | EPSS Score | 1.736% | EPSS Percentile | 82nd percentile |
Description
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
|
openssl 3.0.16-1~deb12u1 (deb)
pkg:deb/debian/openssl@3.0.16-1~deb12u1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=3.0.11-1~deb12u2 | Fixed version | Not Fixed | EPSS Score | 0.132% | EPSS Percentile | 34th percentile |
Description
|
gcc-12 12.2.0-14+deb12u1 (deb)
pkg:deb/debian/gcc-12@12.2.0-14%2Bdeb12u1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=12.2.0-14+deb12u1 | Fixed version | Not Fixed | EPSS Score | 0.051% | EPSS Percentile | 16th percentile |
Description
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
|
shadow 1:4.13+dfsg1-1+deb12u1 (deb)
pkg:deb/debian/shadow@1%3A4.13%2Bdfsg1-1%2Bdeb12u1?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=1:4.13+dfsg1-1+deb12u1 | Fixed version | Not Fixed | EPSS Score | 0.269% | EPSS Percentile | 50th percentile |
Description
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.
- shadow (unimportant)
See #290803, on Debian LOG_UNKFAIL_ENAB in login.defs is set to no so
unknown usernames are not recorded on login failures
|
util-linux 2.38.1-5+deb12u3 (deb)
pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?os_distro=bookworm&os_name=debian&os_version=12

Affected range | >=2.38.1-5+deb12u3 | Fixed version | Not Fixed | EPSS Score | 0.025% | EPSS Percentile | 5th percentile |
Description
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
|