Debian LTS Essential and Critical Security Patch Updates - Page 27
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Quadratic runtime with malformed PDFs missing xref marker has been fixed in PyPDF2, a pure Python PDF library. For Debian 10 buster, this problem has been fixed in version
Issues were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to impersonation of users with a second factor authentication.
Multiple vulnerabilies were fixed in php-dompdf a CSS 2.1 compliant HTML to PDF converter, written in PHP. CVE-2021-3838
It was discovered that there was an issue in ruby-doorkeeper, a OAuth2 provider for Ruby on Rails applications. Doorkeeper automatically processed authorization requests without user consent for public clients that have been previously approved, but public
Multiple security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to information disclosure or impersonation.
Multiple vulnerabilties have been found in yajl, a JSON parser / small validating JSON generator# written in ANSI C, which potentially can cause memory corruption or DoS.
A Client Authentication Bypass vulnerability has been discovered in the concurrent, real-time, distributed functional language Erlang. Impacted are those who are running an ssl/tls/dtls server using the ssl application either directly or indirectly via other applications. Note that the
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version
A security issue was discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure when SQLite files are created within a data directory that has weak permissions.
Kokorin Vsevolod discovered a Prototype Pollution vulnerability in node-tough-cookie, a RFC6265 Cookies and Cookie Jar library for node.js. The issue is due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode.
A potential Cross Site Scripting (XSS) vulnerablity (CVE-2022-36180) and session handling vulnerability (CVE-2022-36179 )have been found in fusiondirectory, a Web Based LDAP Administration Program.
The source package ocsinventory-server, a Hardware and software inventory tool has been updated to address the API change in php-cas due to CVE-2022-39369, see DLA 3485-1 for details.
A vulnerability has been found in phpCAS, a Central Authentication Service client library in php, which may allow an attacker to gain access to a victim's account on a vulnerable CASified service without victim's knowledge, when the victim visits attacker's website while
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.
It was discovered that the Nullsoft Scriptable Install System (NSIS) before version 3.09 mishandles access control for the uninstaller directory.
debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. For Debian 10 buster, GPG-keys for 12/bullseye Debian release are added
An out-of-bounds read was found in sctp_load_addresses_from_init. For Debian 10 buster, this problem has been fixed in version 0.9.3.0+20190127-2+deb10u1.
A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Two denial of service vulnerabilities have been discovered in golang-yaml.v2, a library which provides YAML support for the Go language.
A memory leak has been found in yajl, a JSON parser / small validating JSON generator written in ANSI C, which might allow an attacker to cause an out of memory situation and potentially causing a crash.