Debian 10694 Published by

Debian GNU/Linux has received several security updates, including a Chromium update, Aide security updates, and a PostgreSQL-13 security update:

Debian GNU/Linux 10 (Buster) Extended LTS:
ELA-1499-1 aide security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4272-1] aide security update
[DLA 4273-1] postgresql-13 security update

Debian GNU/Linux 12 (Bookworm) and 13 (Trixie):
[DSA 5976-1] chromium security update
[DSA 5977-1] aide security update



[SECURITY] [DSA 5976-1] chromium security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5976-1 security@debian.org
https://www.debian.org/security/ Andres Salomon
August 14, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium
CVE ID : CVE-2025-8879 CVE-2025-8880 CVE-2025-8881 CVE-2025-8882
CVE-2025-8901

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For the oldstable distribution (bookworm), these problems have been fixed
in version 139.0.7258.127-1~deb12u1.

For the stable distribution (trixie), these problems have been fixed in
version 139.0.7258.127-1~deb13u1. Additionally this update includes fixes
for CVE-2025-8576, CVE-2025-8577, CVE-2025-8578, CVE-2025-8579,
CVE-2025-8580, CVE-2025-8581, CVE-2025-8582, and CVE-2025-8583.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4272-1] aide security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4272-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Thorsten Alteholz
August 14, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : aide
Version : 0.17.3-4+deb11u3
CVE ID : CVE-2025-54389 CVE-2025-54409

Rajesh Pangare discovered two vulnerabilities in aide, an advanced
intrusion detection system. A local attacker can take advantage of these
flaws to hide the addition or removal of a file from the the report,
tamper with the log output, or cause aide to crash during report
printing or database listing.

For Debian 11 bullseye, these problems have been fixed in version
0.17.3-4+deb11u3.

We recommend that you upgrade your aide packages.

For the detailed security status of aide please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/aide

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 5977-1] aide security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5977-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 14, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : aide
CVE ID : CVE-2025-54389 CVE-2025-54409

Rajesh Pangare discovered two vulnerabilities in aide, an advanced
intrusion detection system. A local attacker can take advantage of these
flaws to hide the addition or removal of a file from the the report,
tamper with the log output, or cause aide to crash during report
printing or database listing.

For the oldstable distribution (bookworm), these problems have been fixed
in version 0.18.3-1+deb12u4.

For the stable distribution (trixie), these problems have been fixed in
version 0.19.1-2+deb13u1.

We recommend that you upgrade your aide packages.

For the detailed security status of aide please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/aide

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1499-1 aide security update


Package : aide
Version : 0.16.1-1+deb10u2 (buster)

Related CVEs :
CVE-2025-54409

Rajesh Pangare discovered a vulnerability in aide, an advanced
intrusion detection system. A local attacker can take advantage of these
flaws to crash aide during report printing.


ELA-1499-1 aide security update



[SECURITY] [DLA 4273-1] postgresql-13 security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4273-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
August 14, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : postgresql-13
Version : 13.22-0+deb11u1
CVE IDs : CVE-2025-8713 CVE-2025-8714 CVE-2025-8715

It was discovered that there were a number of vulnerabilities in
postgresql-13, the widely-popular database management system:

* CVE-2025-8713: The fix for CVE-2017-7484 (plus followup fixes),
was intended to prevent leaky functions from being applied to
statistics data for columns that the calling user does not have
permission to read. Some gaps in that protection were found and
addressed.

* CVE-2025-8714: Prevent pg_dump scripts from being used to attack
the user running the restore. An attacker who had gained
superuser-level control over the source server might have been
able to cause it to emit text that would be interpreted as psql
meta-commands.

* CVE-2025-8715: Convert newlines to spaces in names included in
comments in pg_dump output, because names containing newlines
offered the ability to inject arbitrary SQL commands into the
output script.

For Debian 11 bullseye, these problems have been fixed in version
13.22-0+deb11u1. Thanks to Christoph Berg (myon) for preparing this
upload.

We recommend that you upgrade your postgresql-13 packages.

For the detailed security status of postgresql-13 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-13

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS