Debian Essential And Critical Security Patch Updates - Page 283
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
This update fixes the second problem from the original advisory.
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.
By specifying a small packet length an attacker is able to overflow a buffer and execute code under the user id that runs pptpd, probably root.
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.
Unfortunately yesterday's update for mime-support did not exactly work as expected, which requires an update.
When a temporary file is to be used it is created insecurely, allowing an attacker to overwrite arbitrary under the user id of the person executing run-mailcap, most probably root.
There is a buffer overflow, triggered by a char to int conversion, in the address parsing code in sendmail.
When the connection list is full, rinetd resizes the list in order to store the new incoming connection. However, this is done improperly, resulting in a denial of service and potentially execution of arbitrary code.
Applications that are linked against the openssl library are generally vulnerable to attacks that could leak the server's private key or make the encrypted sessiondecryptable otherwise.
The correction for CAN-2003-0144 for the old stable distribution (potato) was a little bit too strict apparently and this update corrects this.
A malicious server could craft special reply strings, triggering the client to write beyond buffer boundaries.
A file is created in an insecure fashion, which could allow a local attacker to overwrite files owned by a user who invokes ps2epsi.
psbanner, a printer filter, insecurely creates a temporary file for debugging purpose when it is configured as filter.
The KDE team discoverd a vulnerability in the way KDE uses Ghostscript software for processing of PostScript (PS) and PDF files.
The manner in which the quota information file is created is unsafe.
Due to overzealous applied patches, the security update DSA 269-1introduced problems in some installations, causing the hprop serviceto fail.
There is an integer overflow in the xdrmem_getbytes() function which is also present in GNU libc.