You are here
Debian Security
DSA-6024-1 ghostscript - security update
Multiple security issues were discovered in Ghostscript, the GPL
PostScript/PDF interpreter, which could result in denial of service and
potentially the execution of arbitrary code if malformed document files
are processed.
Categories: Security
DSA-6023-1 tiff - security update
It was discovered that missing input sanitising in the libtiff library
could result in denial of service or potentially the execution of
arbitrary code if malformed image files are processed.
Categories: Security
DSA-6022-1 valkey - security update
Multiple security issues were discovered in the Lua scripting interface
of Valkey, a persistent key-value database, which could result in the
execution of arbitrary code or denial of service.
Categories: Security
DSA-6021-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6020-1 redis - security update
Multiple security issues were discovered in the Lua scripting interface
of Redis, a persistent key-value database, which could result in the
execution of arbitrary code or denial of service.
Categories: Security
DSA-6019-1 dovecot - security update
A flaw with the authentication cache management was discovered in the
Dovecot email server, which could result in users being logged in as the
wrong user in certain configurations.
Categories: Security
DSA-6018-1 gegl - security update
A buffer overflow was discovered in the RGBE/HDR parser of GEGL, a
graph-based image processing library, which could result in denial of
service or the execution of arbitrary code if malformed files are
processed.
Categories: Security
DSA-6017-1 haproxy - security update
Oula Kivalo reported that HAProxy, a fast and reliable load balancing
reverse proxy, is prone to a denial of service vulnerability when
parsing JSON numbers.
Categories: Security
DSA-6016-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-6015-1 openssl - security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit, which may result in denial of service or
information leaks.
Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20250930.txt
Categories: Security
DSA-6014-1 gimp - security update
Several vulnerabilities were discovered in GIMP, the GNU Image
Manipulation Program, which could result in denial of service or
potentially the execution of arbitrary code if malformed Farbfeld,
Wireless Bitmap, DICOM or Apple Icon images are opened.
Categories: Security
DSA-6013-1 node-tar-fs - security update
It was discovered that the symlink validation in node-tar-fs, a Node.js
module that provides filesystem-like access to tar files, could be
bypassed.
Categories: Security
DSA-6003-2 firefox-esr - regression update
Firefox 140.3.1 has been released, which fixes connection errors with
some sites; if HTTP/3 connections failed, the fallback is now handled
more gracefully.
Categories: Security
DSA-6012-1 nncp - security update
Eugene Medvedev discovered that nncp, a package facilitating secure
store-and-forward file and mail exchange, was susceptible to path
traversal with the freq and file commands.
Categories: Security
DSA-6011-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.
Debian follows the Thunderbird upstream releases. Support for the 128.x series has ended, so starting with this update we're now following the 140.x series.
Categories: Security
DSA-6010-1 chromium - security update
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Categories: Security
DSA-5979-2 libxslt - regression update
The update for libxslt announced in DSA 5979-1 introduced a regression
while back porting the upstream deterministic generate-id implementation,
which makes the generated IDs may remain in a non-deterministic order.
Categories: Security
DSA-6009-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Categories: Security
DSA-6008-1 linux - security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
Categories: Security
DSA-6007-1 ffmpeg - security update
Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
Categories: Security