You are here
Security
DSA-6116-1 chromium - security update
A security issue was discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6115-1 gimp - security update
A buffer overflow was discovered in GIMP, the GNU Image Manipulation
Program, which could result in denial of service or potentially the
execution of arbitrary code if malformed PSP images are opened.
Categories: Security
DSA-6114-1 pyasn1 - security update
It was discovered that pyasn1, a generic ASN.1 library for Python, is
prone to a denial of service vulnerability, which may result in memory
exhaustion from malformed OID/RELATIVE-OID with excessive continuation
octets.
Categories: Security
DSA-6113-1 openssl - security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit, which may result in denial of service,
information leaks, or potentially remote code execution.
Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20260127.txt
Categories: Security
DSA-6112-1 openjdk-21 - security update
Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in incorrect certificate validation, CRLF
injection or man-in-the-middle attacks.
Categories: Security
DSA-6111-1 imagemagick - security update
This update fixes multiple vulnerabilities in Imagemagick, which could
result in denial of service via MSL scripts or potentially the execution
of arbitrary code if malformed XBM images are processed.
Categories: Security
DSA-6110-1 openjdk-17 - security update
Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in incorrect certificate validation,
CRLF injection or man-in-the-middle attacks.
Categories: Security
DSA-6109-1 incus - security update
Two security issues were discovered in Incus, a system container and
virtual machine manager, which could result the in execution of arbitrary
commands via malformed images.
Categories: Security
DSA-6102-2 python-urllib3 - regression update
The update for python-urllib3 announced in DSA 6102-1 introduced a
regression in the patch meant to address CVE-2026-21441 for the
oldstable distribution (bookworm). Updated packages are now available to
correct this issue.
Categories: Security
DSA-6108-1 chromium - security update
A security issue was discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6107-1 bind9 - security update
Vlatko Kosturjak discovered that BIND, a DNS server implementation, does
not properly handle malformed BRID/HHIT records, which may result in
denial of service (named daemon crash).
Categories: Security
DSA-6106-1 inetutils - security update
Kyu Neushwaistein discovered that telnetd from inetutils does not
sanitize the USER environment variable before passing it on to login. A
remote attacker can take advantage of this flaw to login as root,
bypassing normal authentication processes.
Categories: Security
DSA-6105-1 modsecurity-crs - security update
It was discovered that one of the rules in the OWASP ModSecurity Core
Rule Set parsed some multipart requests incorrectly.
Categories: Security
DSA-6104-1 python-keystonemiddleware - security update
Grzegorz Grasza discovered a vulnerability in the Openstack middleware to
provide authentication and authorization features to web services other
than Keystone: If an external OAuth provider is configured,
authentication headers are insufficiently sanitised, which could result
in privilege escalation or user impersonation.
The oldstable distribution (bookworm) is not affected.
Categories: Security
DSA-6103-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.
Categories: Security
DSA-6102-1 python-urllib3 - security update
Several vulnerabilities were discovered in python-urllib3, a HTTP
library with thread-safe connection pooling for Python3, which could
result in denial of service or request forgery.
Categories: Security
DSA-6101-1 firefox-esr - security update
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, sandbox escape, information disclosure or spoofing.
Categories: Security
DSA-6100-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6099-1 python-parsl - security update
Viral Vaghela discovered an SQL injection vulnerability in Parsl, a
parallel scripting library for Python.
Categories: Security
DSA-6098-1 net-snmp - security update
A vulnerability was discovered in the snmptrapd daemon in net-snmp, a
suite of Simple Network Management Protocol applications, which could
result in denial of service or the execution of arbitrary code.
Categories: Security
