You are here

Debian Security

Subscribe to Debian Security feed
Debian Security Advisories
Updated: 1 hour 6 min ago

DSA-6013-1 node-tar-fs - security update

28 September, 2025 - 00:00
It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.

https://security-tracker.debian.org/tracker/DSA-6013-1

Categories: Security

DSA-6003-2 firefox-esr - regression update

28 September, 2025 - 00:00
Firefox 140.3.1 has been released, which fixes connection errors with some sites; if HTTP/3 connections failed, the fallback is now handled more gracefully.

https://security-tracker.debian.org/tracker/DSA-6003-2

Categories: Security

DSA-6012-1 nncp - security update

26 September, 2025 - 00:00
Eugene Medvedev discovered that nncp, a package facilitating secure store-and-forward file and mail exchange, was susceptible to path traversal with the freq and file commands.

https://security-tracker.debian.org/tracker/DSA-6012-1

Categories: Security

DSA-6011-1 thunderbird - security update

25 September, 2025 - 00:00
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code.

Debian follows the Thunderbird upstream releases. Support for the 128.x series has ended, so starting with this update we're now following the 140.x series.

https://security-tracker.debian.org/tracker/DSA-6011-1

Categories: Security

DSA-6010-1 chromium - security update

25 September, 2025 - 00:00
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-6010-1

Categories: Security

DSA-5979-2 libxslt - regression update

25 September, 2025 - 00:00
The update for libxslt announced in DSA 5979-1 introduced a regression while back porting the upstream deterministic generate-id implementation, which makes the generated IDs may remain in a non-deterministic order.

https://security-tracker.debian.org/tracker/DSA-5979-2

Categories: Security

DSA-6009-1 linux - security update

22 September, 2025 - 00:00
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-6009-1

Categories: Security

DSA-6008-1 linux - security update

22 September, 2025 - 00:00
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

https://security-tracker.debian.org/tracker/DSA-6008-1

Categories: Security

DSA-6007-1 ffmpeg - security update

21 September, 2025 - 00:00
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

https://security-tracker.debian.org/tracker/DSA-6007-1

Categories: Security

DSA-6006-1 jetty12 - security update

19 September, 2025 - 00:00
This update for Jetty, a Java servlet engine and web server, addresses a protocol-level vulnerability in HTTP/2 support also referred to as "MadeYouReset".

https://security-tracker.debian.org/tracker/DSA-6006-1

Categories: Security

DSA-6005-1 jetty9 - security update

19 September, 2025 - 00:00
This update for Jetty, a Java servlet engine and web server, addresses a protocol-level vulnerability in HTTP/2 support also referred to as "MadeYouReset".

https://security-tracker.debian.org/tracker/DSA-6005-1

Categories: Security

DSA-6004-1 chromium - security update

19 September, 2025 - 00:00
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that an exploit for CVE-2025-10585 exists in the wild.

https://security-tracker.debian.org/tracker/DSA-6004-1

Categories: Security

DSA-6003-1 firefox-esr - security update

18 September, 2025 - 00:00
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy.

Debian follows the extended support releases (ESR) of Firefox. So starting with this update we're now following the 140.x releases.

Between 128.x and 140.x, Firefox has seen a number of feature updates. For more information please refer to https://www.firefox.com/en-US/firefox/140.0esr/releasenotes/

https://security-tracker.debian.org/tracker/DSA-6003-1

Categories: Security

DSA-6002-1 node-sha.js - security update

16 September, 2025 - 00:00
It was discovered that Node sha.js, an implementation of the SHA family hash functions in pure JavaScript, performed incomplete type checks.

https://security-tracker.debian.org/tracker/DSA-6002-1

Categories: Security

Pages