You are here
Security
DSA-6120-1 tomcat10 - security update
Several security vulnerabilities have been found in Tomcat 10, a Java web server and servlet engine. This update improves the handling of HTTP/2 connections and corrects various flaws which can lead to uncontrolled resource consumption and a denial of service.
Categories: Security
DSA-6119-1 openjdk-25 - security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in incorrect certificate validation, CRLF injection or
man-in-the-middle attacks.
Categories: Security
DSA-6118-1 thunderbird - security update
A security issue was discovered in Thunderbird, which could result in
information disclosure
Categories: Security
DSA-6117-1 python-django - security update
Multiple security issues were found in Django, a Python web development
framework, which could result in SQL injection, directory traversal
or denial of service.
Categories: Security
DSA-6116-1 chromium - security update
A security issue was discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6115-1 gimp - security update
A buffer overflow was discovered in GIMP, the GNU Image Manipulation
Program, which could result in denial of service or potentially the
execution of arbitrary code if malformed PSP images are opened.
Categories: Security
DSA-6114-1 pyasn1 - security update
It was discovered that pyasn1, a generic ASN.1 library for Python, is
prone to a denial of service vulnerability, which may result in memory
exhaustion from malformed OID/RELATIVE-OID with excessive continuation
octets.
Categories: Security
DSA-6113-1 openssl - security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit, which may result in denial of service,
information leaks, or potentially remote code execution.
Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20260127.txt
Categories: Security
DSA-6112-1 openjdk-21 - security update
Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in incorrect certificate validation, CRLF
injection or man-in-the-middle attacks.
Categories: Security
DSA-6111-1 imagemagick - security update
This update fixes multiple vulnerabilities in Imagemagick, which could
result in denial of service via MSL scripts or potentially the execution
of arbitrary code if malformed XBM images are processed.
Categories: Security
DSA-6110-1 openjdk-17 - security update
Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in incorrect certificate validation,
CRLF injection or man-in-the-middle attacks.
Categories: Security
DSA-6109-1 incus - security update
Two security issues were discovered in Incus, a system container and
virtual machine manager, which could result the in execution of arbitrary
commands via malformed images.
Categories: Security
DSA-6102-2 python-urllib3 - regression update
The update for python-urllib3 announced in DSA 6102-1 introduced a
regression in the patch meant to address CVE-2026-21441 for the
oldstable distribution (bookworm). Updated packages are now available to
correct this issue.
Categories: Security
DSA-6108-1 chromium - security update
A security issue was discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6107-1 bind9 - security update
Vlatko Kosturjak discovered that BIND, a DNS server implementation, does
not properly handle malformed BRID/HHIT records, which may result in
denial of service (named daemon crash).
Categories: Security
DSA-6106-1 inetutils - security update
Kyu Neushwaistein discovered that telnetd from inetutils does not
sanitize the USER environment variable before passing it on to login. A
remote attacker can take advantage of this flaw to login as root,
bypassing normal authentication processes.
Categories: Security
DSA-6105-1 modsecurity-crs - security update
It was discovered that one of the rules in the OWASP ModSecurity Core
Rule Set parsed some multipart requests incorrectly.
Categories: Security
DSA-6104-1 python-keystonemiddleware - security update
Grzegorz Grasza discovered a vulnerability in the Openstack middleware to
provide authentication and authorization features to web services other
than Keystone: If an external OAuth provider is configured,
authentication headers are insufficiently sanitised, which could result
in privilege escalation or user impersonation.
The oldstable distribution (bookworm) is not affected.
Categories: Security
DSA-6103-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.
Categories: Security
DSA-6102-1 python-urllib3 - security update
Several vulnerabilities were discovered in python-urllib3, a HTTP
library with thread-safe connection pooling for Python3, which could
result in denial of service or request forgery.
Categories: Security
