Debian Installer EOL?

Status
Not open for further replies.

simbar

Customer
Joined
May 12, 2023
Messages
6
Reaction score
1
Your Debian ISO installation is based on Debian(10) buster which seem to have some limited support

Debian 10 has been superseded by Debian 11 (bullseye). Security updates have been discontinued as of June 30th, 2022.

However, buster benefits from Long Term Support (LTS) until the end of June 2024.


Not sure if you are using an LTS version?
Our vulnerability scanner shows a number of issues, that should get fixed by a simple apt-get upgrade. I would expect these to be fixed if you are using the LTS release?
  • Debian Security Update for glibc (DLA 3152-1)
  • Debian Security Update for glibc (DLA 3152-1)
  • Debian Security Update for vim (DLA 3453-1)
  • Debian Security Update for sysstat (DLA 3434-1)
  • Debian Security Update for libraw (DLA 3433-1)
  • Debian Security Update for Open Secure Sockets Layer (OpenSSL) (DLA 3449-1)
  • Debian Security Update for postgresql-11 (DLA 3422-1)
  • OpenSSH Information Disclosure Vulnerability (Generic)







 
https://wiki.debian.org/LTS
"the Debian LTS team takes over security maintenance of the various releases once the Debian Security team stops its work"

Re: updates, it is recommended to not update Debian installs yourself. If (only if) automatic updates are enabled, 3CX will install OS updates they have tested against 3CX. If one performs a manual 3CX update this is not done. To control update timing one can enable automatic updates when desired.
 
We do have auto updates enabled. Our version is showing as 18.0 (Build 424)
The only updates showing are the optional beta release New 18.0 Update 7A Beta Security

I would expect 3CX to be supplying necessary operating system security patches via there update mechanism. Our vulnerability scanner shows the OS is missing security updates released from Debain.
apt-get upgrade isn't even showing any additional updates to install, which suggests 3CX apt repos don't contain the patches.

Here is one of the issues
https://lists.debian.org/debian-lts-announce/2023/05/msg00014.html
Package : postgresql-11
Version : 11.20-0+deb10u1
CVE ID : CVE-2023-2454 CVE-2023-2455

Two security issues were found in PostgreSQL, which may result in
privilege escalation or incorrect policy enforcement.

For Debian 10 buster, these problems have been fixed in version
11.20-0+deb10u1.

Version installed on 3cx server:
dpkg -s postgresql-11 | grep Version
Version: 11.19-0+deb10u1
 
Hi, we had feedback from the appropriate team which manages the security patches and they're
finalizing testing and they will push security updates sometime next week.
 
  • Like
Reactions: Alphabetic
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet