Debian LTS Essential and Critical Security Patch Updates - Page 34
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.
The previous Imagemagick security update caused a regression in some perl packages due to overly restrictive hardening in a policy update (reading from /etc/ was forbidden). This hardening patch has been removed.
Two important bugs were discovered in xapian-core, a search engine library, that led to potential database corruption on disk full, and incorrectly reporting corruption for a database with replication changesets.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.
Multiple out-of-bounds read vulnerabilities were found in pcre2, a Perl Compatible Regular Expression library, which could result in information disclosure or denial or service.
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, information leak, or potentially the execution of arbitrary code.
It was discovered that there was a potential remote denial of service vulnerability in redis, a popular key-value database. Authenticated users could have used string matching commands (like
ruby-sidekiq, a simple, efficient background processing for Ruby, had a couple of vulnerabilities as follows: CVE-2021-30151
libapache2-mod-auth-mellon, a SAML 2.0 authentication module for Apache, were reported to have the following vulnerabilities. CVE-2019-13038
An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter.
Several vulnerabilities have been discovered in imagemagick that may lead to a privilege escalation, denial of service or information leaks. CVE-2020-19667
This update the wireless regulatory database to version 2022.04.08. In addition, it allows the Linux 5.10 kernel to verify and autoload it. We recommend that you upgrade your wireless-regdb package.
Several issues were found in Kopano Collaboration Platform, a groupware solution, which could cause denial of service or unauthorized access. For Debian 10 buster, these problems have been fixed in version
A security issue has been discovered in xfig, a diagramming tool for the interactive generation of figures under X11. CVE-2021-40241:
Multiple issues were found in libde265, an open source implementation of the h.265 video codec, which may result in denial of service, possibly code execution due to a heap-based buffer overflow or have unspecified other impact.
It was discovered that the fix for CVE-2023-27372 broke (de)activation of plugins with dependencies. For Debian 10 buster, this problem has been fixed in version
Multiple security vulnerabilities have been discovered in Apache HTTP server. CVE-2006-20001
node-css-what was vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable. The exploitation of this vulnerability could be triggered
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
It was discovered that syslog-ng, a system logging daemon, had integer overflow and buffer out-of-bounds issues, which could allow a remote attacker to cause Denial of Service via crafted syslog input.