You are here
Security
DSA-6140-1 gnutls28 - security update
Tim Scheckenbach reported a flaw in GnuTLS, a library implementing the
TLS and SSL protocols. Processing of specially crafted certificates
containing a large number of name constraints may result in denial of
service (resource exhaustion).
Categories: Security
DSA-6139-1 gimp - security update
Several vulnerabilities were discovered in GIMP, the GNU Image
Manipulation Program, which could result in denial of service or
potentially the execution of arbitrary code if malformed PSD, PSP or ICO
files are opened.
Categories: Security
DSA-6138-1 libpng1.6 - security update
A buffer overflow was discovered in libpng, a library implementing an
interface for reading and writing PNG (Portable Network Graphics) files,
which could result in denial of service or potentially the execution
of arbitrary code.
Categories: Security
DSA-6137-1 roundcube - security update
CERT Polska and nullcathedral discovered that roundcube, a skinnable
AJAX based webmail solution for IMAP servers, did not correctly
process and sanitize requests. This would allow an attacker to perform
CSS injection attacks, or leak sensitive information.
Categories: Security
DSA-6136-1 python-django - security update
Multiple security issues were found in Django, a Python web development
framework, which could result in denial of service, information
disclosure, directory traversal or SQL injection.
Categories: Security
DSA-6135-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure. Google is aware that an exploit for CVE-2026-2441 exists
in the wild.
Categories: Security
DSA-6134-1 pdns-recursor - security update
Two vulnerabiliites have been discovered in PDNS Recursor, a resolving
name server which result result in denial of service when processing a
malformed zone file.
Categories: Security
DSA-6133-1 postgresql-17 - security update
Multiple security issues were discovered in PostgreSQL, which may result
in memory disclosure or the execution of arbitrary code.
Categories: Security
DSA-6132-1 postgresql-15 - security update
Multiple security issues were discovered in PostgreSQL, which may result
in memory disclosure or the execution of arbitrary code.
Categories: Security
DSA-6131-1 nginx - security update
A vulnerability has been discovered in Nginx, a high-performance web
and reverse proxy server: If configured to proxy to an upstream TLS
server, a man-in-the-middle injection attack was possible.
Categories: Security
DSA-6130-1 haproxy - security update
Asim Viladi Oglu Manizada reported that HAProxy, a load balancing
reverse proxy, does not properly validate an INITIAL QUIC packet with
specially crafted data, which may result in denial of service (process
crash).
Categories: Security
DSA-6129-1 munge - security update
Titouan Lazard discovered a buffer overflow vulnerability in munge, an
authentication service to create and validate credentials, which may
allow local users to leak the MUNGE cryptographic key and forge
arbitrary credentials.
Additional details can be found in the upstream advisory: https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh
Categories: Security
DSA-6128-1 shaarli - security update
Moritz Woermann discovered that missing input sanitising in Shaarli, a
personal bookmarking service, could result in cross-site scripting.
Categories: Security
DSA-6127-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Categories: Security
DSA-6126-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Categories: Security
DSA-6125-1 usbmuxd - security update
A path traversal vulnerability was discovered in usbmuxd, a multiplexor daemon
used to coordinate USB connections from and to Apple devices (iPhone, iPad,
iPod).
Exploiting this vulnerability enables an unprivileged user to create and delete files named `*.plist` (and, in some cases, arbitrarily named) as the user running the daemon (`usbmux` by default).
Categories: Security
DSA-6124-1 wireshark - security update
Multiple vulnerabilities have been discocvered in Wireshark, a network
protocol analyzer which could result in denial of service or the
execution of arbitrary code.
Categories: Security
DSA-6123-1 xrdp - security update
Denis Skvortsov discovered that xrdp, a Remote Desktop Protocol (RDP)
server, was susceptible to an unauthenticated stack-based buffer
overflow vulnerability, which may result in remote execution of
arbitrary code.
Categories: Security
DSA-6122-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6121-1 tomcat11 - security update
Several security vulnerabilities have been found in Tomcat 11, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service.
Categories: Security
