You are here
Debian Security
DSA-5979-2 libxslt - regression update
    The update for libxslt announced in DSA 5979-1 introduced a regression
while back porting the upstream deterministic generate-id implementation,
which makes the generated IDs may remain in a non-deterministic order.
  
    Categories: Security  
DSA-6009-1 linux - security update
    Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
  
    Categories: Security  
DSA-6008-1 linux - security update
    Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
  
    Categories: Security  
DSA-6007-1 ffmpeg - security update
    Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.
  
    Categories: Security  
DSA-6006-1 jetty12 - security update
    This update for Jetty, a Java servlet engine and web server, addresses
a protocol-level vulnerability in HTTP/2 support also referred to as
"MadeYouReset".
  
    Categories: Security  
DSA-6005-1 jetty9 - security update
    This update for Jetty, a Java servlet engine and web server, addresses a
protocol-level vulnerability in HTTP/2 support also referred to as
"MadeYouReset".
  
    Categories: Security  
DSA-6004-1 chromium - security update
    Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure. Google is aware that an exploit for CVE-2025-10585 exists
in the wild.
  
    Categories: Security  
DSA-6003-1 firefox-esr - security update
    Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, sandbox escape, information disclosure or bypass of the same-origin
policy.
  Debian follows the extended support releases (ESR) of Firefox. So starting with this update we're now following the 140.x releases.
Between 128.x and 140.x, Firefox has seen a number of feature updates. For more information please refer to https://www.firefox.com/en-US/firefox/140.0esr/releasenotes/
    Categories: Security  
DSA-6002-1 node-sha.js - security update
    It was discovered that Node sha.js, an implementation of the SHA family
hash functions in pure JavaScript, performed incomplete type checks.
  
    Categories: Security  
DSA-6001-1 cjson - security update
    It was discovered that cJSON, an ultralightweight JSON parser, performed
insufficient input sanitising, which could result in out-of-bounds
memory access.
  
    Categories: Security  
DSA-5997-1 imagemagick - security update
    Multiple memory corruption vulnerbilities were discovered in imagemagick,
a software suit used for editing and manipulating digital images, which
could lead to information leak, denial of service, and potentially arbitrary
code execution.
  
    Categories: Security  
DSA-6000-1 libcpanel-json-xs-perl - security update
    Michael Hudak discovered a flaw in libcpanel-json-xs-perl, a module for
fast and correct serialising to JSON. An integer buffer overflow causing
a segfault when parsing specially crafted JSON, may allow an attacker to
mount a denial-of-service attack or cause other unspecified impact.
  
    Categories: Security  
DSA-5999-1 libjson-xs-perl - security update
    Michael Hudak discovered a flaw in libjson-xs-perl, a module for
manipulating JSON-formatted data. An integer buffer overflow causing a
segfault when parsing specially crafted JSON, may allow an attacker to
mount a denial-of-service attack or cause other unspecified impact.
  
    Categories: Security  
DSA-5998-1 cups - security update
    Two vulnerabilities were discovered in cups, the Common UNIX Printing
System, which may result in authentication bypass with AuthType
Negotiate or in denial of service (daemon crash).
  
    Categories: Security  
DSA-5996-1 chromium - security update
    Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
  
    Categories: Security  
DSA-5995-1 hsqldb1.8.0 - security update
    Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL
database engine, allowed the execution of spurious scripting commands in
.script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally
used to record the commands input by the database admin to output such a
script. In combination with LibreOffice, an attacker could craft an odb
containing a "database/script" file which itself contained a SCRIPT command
where the contents of the file could be written to a new file whose location
was determined by the attacker.
  
    Categories: Security  
DSA-5994-1 shibboleth-sp - security update
    Florian Stuhlmann discovered a SQL vulnerability in the ODBC plugin in the
Shibboleth Service Provider which may result in information leak.
  For additional information please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20250903.txt
    Categories: Security  
DSA-5993-1 chromium - security update
    Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
  
    Categories: Security  
DSA-5992-1 firebird4.0 - security update
    Two vulnerabilities were discovered in the Firebird database, which may
result in denial of service or authentication bypass.
  
    Categories: Security  
DSA-5991-1 nodejs - security update
    Multiple vulnerabilities were discovered in Node.js, which could result
in denial of service, HTTP request smuggling, privilege escalation, a
side channel attack against PKCS#1 1.5 or a bypass of network import
restrictions.
  
    Categories: Security  
      