Debian LTS Essential and Critical Security Patch Updates - Page 16
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid's HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow
It was discovered that Exim, a mail transport agent, can be induced to accept a second message embedded as part of the body of a first message in certain configurations where PIPELINING or CHUNKING on incoming connections is offered.
Apache Tomcat 9, a Servlet and JSP engine, was vulnerable. An Improper Input Validation vulnerability was present. and Tomcat did not correctly parse HTTP trailer headers.
Corentin BAYET, Etienne HELLUY-LAFONT and Luca MORO of Synacktiv discovered a symlink redirection vulnerability in Netatalk, the Apple Filing Protocol service. The create_appledesktop_folder function of netatalk can be used to unsafely move files outside the shared volume using the "mv" system utility.
It was discovered that php-guzzlehttp-psr7, a PSR-7 message implementation, performed improper header parsing, which may lead to information disclosure or authorization bypass.
Even Rouault discovered that xerces-c, a validating XML parser library for C++, was vulnerable to integer overflow via crafted .xsd files, which can lead to out-of-bounds access.
Multiple vulnerabilities have been discovered in LibreOffice an office productivity software suite: CVE-2020-12801
Le Dinh Hai discovered that libspreadsheet-parseexcel-perl, a Perl module allowing information extraction from Excel spreadsheets, improperly sanitizes directives in dynamically evaluated code.
A reachable assertion issue has been discovered in tinyxml, a C++ XML parsing library, which could lead to denial of service via a crafted XML document with a '\0' located after whitespace.
An issue has been found in cjson, an ultralightweight JSON parser in ANSI C. The issue is related to a segmentation violation in function cJSON_InsertItemInArray().
Three issues have been found in libde265, an open H.265 video codec implementation. All issues are related to heap-buffer-overflow or global buffer overflow in different functions.
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing of signed PGP/MIME and SMIME emails.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or clickjacking.
Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457
Ansible a configuration management, deployment, and task execution system was affected by multiple vulnerabilities. CVE-2019-10206
Several vulnerabilities have been discovered in OpenSSH, an implementation of the SSH protocol suite. CVE-2021-41617
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file.
Two security issues were found in Curl, an easy-to-use client-side URL transfer library and command line tool. Additionally, the command line tool does now:
Multiple security issues were discovered in SPIP, a content management system, which could lead to denial of service or information disclosure. For Debian 10 buster, this problem has been fixed in version