You are here

Security

DSA-6024-1 ghostscript - security update

Debian Security - 11 October, 2025 - 00:00
Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed.

https://security-tracker.debian.org/tracker/DSA-6024-1

Categories: Security

DSA-6023-1 tiff - security update

Debian Security - 10 October, 2025 - 00:00
It was discovered that missing input sanitising in the libtiff library could result in denial of service or potentially the execution of arbitrary code if malformed image files are processed.

https://security-tracker.debian.org/tracker/DSA-6023-1

Categories: Security

DSA-6022-1 valkey - security update

Debian Security - 9 October, 2025 - 00:00
Multiple security issues were discovered in the Lua scripting interface of Valkey, a persistent key-value database, which could result in the execution of arbitrary code or denial of service.

https://security-tracker.debian.org/tracker/DSA-6022-1

Categories: Security

DSA-6021-1 chromium - security update

Debian Security - 9 October, 2025 - 00:00
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-6021-1

Categories: Security

DSA-6020-1 redis - security update

Debian Security - 8 October, 2025 - 00:00
Multiple security issues were discovered in the Lua scripting interface of Redis, a persistent key-value database, which could result in the execution of arbitrary code or denial of service.

https://security-tracker.debian.org/tracker/DSA-6020-1

Categories: Security

DSA-6019-1 dovecot - security update

Debian Security - 5 October, 2025 - 00:00
A flaw with the authentication cache management was discovered in the Dovecot email server, which could result in users being logged in as the wrong user in certain configurations.

https://security-tracker.debian.org/tracker/DSA-6019-1

Categories: Security

DSA-6018-1 gegl - security update

Debian Security - 3 October, 2025 - 00:00
A buffer overflow was discovered in the RGBE/HDR parser of GEGL, a graph-based image processing library, which could result in denial of service or the execution of arbitrary code if malformed files are processed.

https://security-tracker.debian.org/tracker/DSA-6018-1

Categories: Security

DSA-6017-1 haproxy - security update

Debian Security - 3 October, 2025 - 00:00
Oula Kivalo reported that HAProxy, a fast and reliable load balancing reverse proxy, is prone to a denial of service vulnerability when parsing JSON numbers.

https://security-tracker.debian.org/tracker/DSA-6017-1

Categories: Security

DSA-6016-1 chromium - security update

Debian Security - 2 October, 2025 - 00:00
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-6016-1

Categories: Security

DSA-6015-1 openssl - security update

Debian Security - 1 October, 2025 - 00:00
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in denial of service or information leaks.

Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20250930.txt

https://security-tracker.debian.org/tracker/DSA-6015-1

Categories: Security

DSA-6014-1 gimp - security update

Debian Security - 28 September, 2025 - 00:00
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed Farbfeld, Wireless Bitmap, DICOM or Apple Icon images are opened.

https://security-tracker.debian.org/tracker/DSA-6014-1

Categories: Security

DSA-6013-1 node-tar-fs - security update

Debian Security - 28 September, 2025 - 00:00
It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.

https://security-tracker.debian.org/tracker/DSA-6013-1

Categories: Security

DSA-6003-2 firefox-esr - regression update

Debian Security - 28 September, 2025 - 00:00
Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.

https://security-tracker.debian.org/tracker/DSA-6003-2

Categories: Security

DSA-6012-1 nncp - security update

Debian Security - 26 September, 2025 - 00:00
Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.

https://security-tracker.debian.org/tracker/DSA-6012-1

Categories: Security

DSA-6011-1 thunderbird - security update

Debian Security - 25 September, 2025 - 00:00
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code.

Debian follows the Thunderbird upstream releases. Support for the 128.x series has ended, so starting with this update we're now following the 140.x series.

https://security-tracker.debian.org/tracker/DSA-6011-1

Categories: Security

DSA-6010-1 chromium - security update

Debian Security - 25 September, 2025 - 00:00
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-6010-1

Categories: Security

DSA-5979-2 libxslt - regression update

Debian Security - 25 September, 2025 - 00:00
The update for libxslt announced in DSA 5979-1 introduced a regression while back porting the upstream deterministic generate-id implementation, which makes the generated IDs may remain in a non-deterministic order.

https://security-tracker.debian.org/tracker/DSA-5979-2

Categories: Security

DSA-6009-1 linux - security update

Debian Security - 22 September, 2025 - 00:00
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-6009-1

Categories: Security

DSA-6008-1 linux - security update

Debian Security - 22 September, 2025 - 00:00
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-6008-1

Categories: Security

DSA-6007-1 ffmpeg - security update

Debian Security - 21 September, 2025 - 00:00
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

https://security-tracker.debian.org/tracker/DSA-6007-1

Categories: Security

Pages

Subscribe to Creative Contingencies aggregator - Security