Debian Security

Subscribe to Debian Security feed
Debian Security Advisories
Updated: 55 min 20 sec ago

DSA-2403 php5 - code injection

2 February, 2012 - 00:00

Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.

Categories: Security

DSA-2402 iceape - several vulnerabilities

2 February, 2012 - 00:00

Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey:

Categories: Security

DSA-2401 tomcat6 - several vulnerabilities

2 February, 2012 - 00:00

Several vulnerabilities have been found in Tomcat, a servlet and JSP engine:

Categories: Security

DSA-2400 iceweasel - several vulnerabilities

2 February, 2012 - 00:00

Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.

Categories: Security

DSA-2399 php5 - several vulnerabilities

31 January, 2012 - 00:00

Several vulnerabilities have been discovered in PHP, the web scripting language. The Common Vulnerabilities and Exposures project identifies the following issues:

Categories: Security

DSA-2398 curl - several vulnerabilities

30 January, 2012 - 00:00

Several vulnerabilities have been discovered in cURL, an URL transfer library. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security

DSA-2397 icu - buffer underflow

29 January, 2012 - 00:00

It was discovered that a buffer overflow in the Unicode library ICU could lead to the execution of arbitrary code.

Categories: Security

DSA-2396 qemu-kvm - buffer underflow

27 January, 2012 - 00:00

Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of KVM, a solution for full virtualization on x86 hardware, which could result in denial of service or privilege escalation.

Categories: Security

DSA-2395 wireshark - buffer underflow

27 January, 2012 - 00:00

Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code (CVE-2012-0068).

Categories: Security

DSA-2394 libxml2 - several vulnerabilities

27 January, 2012 - 00:00

Many security problems have been fixed in libxml2, a popular library to handle XML data files.

Categories: Security

DSA-2393 bip - buffer overflow

25 January, 2012 - 00:00

Julien Tinnes reported a buffer overflow in the Bip multiuser IRC proxy which may allow arbitrary code execution by remote users.

Categories: Security

DSA-2392 openssl - out-of-bounds read

23 January, 2012 - 00:00

Antonio Martin discovered a denial-of-service vulnerability in OpenSSL, an implementation of TLS and related protocols. A malicious client can cause the DTLS server implementation to crash. Regular, TCP-based TLS is not affected by this issue.

Categories: Security

DSA-2301 rails - several vulnerabilities

23 January, 2012 - 00:00

Several vulnerabilities have been discovered in Rails, the Ruby web application framework. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security

DSA-2391 phpmyadmin - several vulnerabilities

22 January, 2012 - 00:00

Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security

DSA-2389 linux-2.6 - privilege escalation/denial of service/information leak

15 January, 2012 - 00:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security

DSA-2390 openssl - several vulnerabilities

15 January, 2012 - 00:00

Several vulnerabilities were discovered in OpenSSL, an implementation of TLS and related protocols. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

Categories: Security

DSA-2388 t1lib - several vulnerabilities

14 January, 2012 - 00:00

Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.

Categories: Security

DSA-2387 simplesamlphp - insufficient input sanitation

11 January, 2012 - 00:00

timtai1 discovered that simpleSAMLphp, an authentication and federation platform, is vulnerable to a cross site scripting attack, allowing a remote attacker to access sensitive client data.

Categories: Security

DSA-2386 openttd - several vulnerabilities

10 January, 2012 - 00:00

Several vulnerabilities have been discovered in OpenTTD, a transport business simulation game. Multiple buffer overflows and off-by-one errors allow remote attackers to cause denial of service.

Categories: Security

DSA-2385 pdns - packet loop

10 January, 2012 - 00:00

Ray Morris discovered that the PowerDNS authoritative server responds to response packets. An attacker who can spoof the source address of IP packets can cause an endless packet loop between a PowerDNS authoritative server and another DNS server, leading to a denial of service.

Categories: Security

Pages