Debian LTS Essential and Critical Security Patch Updates - Page 30
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
sssd 1.16.3-3.2+deb10u1 (DLA 3436-1) had a broken upgrade path from version 1.16.3-3.2. One could upgrade sssd-common to 1.16.3-3.2+deb10u1 while leaving
It was discovered that there was a potential arbitrary code execution vulnerability in libwebp, a library to support the WebP image compression format.
It was discovered that there was a potential denial-of-service (DoS) attack in the Kamailio SIP telephony server. This was caused by the Kamailio server mishandling INVITE requests with duplicated fields.
Two security issues have been discovered in libssh, a tiny C SSH library, which may allows an remote authenticated user to cause a denial of service or inject arbitrary commands.
Multiple vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.
Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase leak.
It was discovered that sysstat, a system performance tools for Linux, incompletely fixed CVE-2022-39377 (as published in DLA-3188-1), which could lead to crashes and possibly remote code execution.
Buffer Overflow vulnerabilities were found in libraw, a raw image decoder library, which could lead to application crash or privilege escalation.
Multiple security issues were discovered in Python, an interactive high-level object-oriented language. An attacker may cause command injection, denial of service (DoS), request smuggling and port scanning.
node-nth-check, a NodeJS module module used to parse and compile nth-checks, as they are found in CSS 3's nth-child() and nth-last-of-type(). This module was vulnerable to a regular expression denial of service
Two vulnerabilities have been fixed in sqlite (V2) which which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact.
It was discovered that missing input sanitising in cups-filters, when using the Backend Error Handler (beh) backend to create an accessible network printer, may result in the execution of arbitrary commands.
Multiple vulnerabilities were fixed in imagemagick, a software suite, used for editing and manipulating digital images. CVE-2021-20176
Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed.
Multiple security vulnerabilities have been discovered in netatalk, the Apple Filing Protocol service, which allow remote attackers to disclose sensitive information, cause a denial of service or execute arbitrary code.
Erik Krogh Kristensen discovered that sqlparse, a non-validating SQL parser, contained a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service).
Martin Wennberg discovered that python-ipaddress, a backport of Python 3's ipaddress module, improperly computed hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a
It was discovered that there was a potential credential stealing attack in epiphany-browser, the default GNOME web browser. When using a sandboxed Content Security Policy (CSP) or the HTML
Two security issues were found in PostgreSQL, which may result in privilege escalation or incorrect policy enforcement. For Debian 10 buster, these problems have been fixed in version
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version