Debian LTS Essential and Critical Security Patch Updates - Page 36
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Two vulnerabilities have been found in the ClamAV antivirus toolkit, which could result in arbitrary code execution or information disclosure when parsing maliciously crafted HFS+ or DMG files.
Multiple security vulnerabilities have been discovered in nss, the Network Security Service libraries. CVE-2020-6829
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in incomplete encryption, side channel attacks, denial of service or information disclosure.
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version
It was discovered that in c-ares, an asynchronous name resolver library, the config_sortlist function is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow and thus may cause a denial of service.
runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation.
Hubert Kario discovered a timing side channel in the RSA decryption implementation of the GNU TLS library. For Debian 10 buster, this problem has been fixed in version
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-23529
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.
A security vulnerability was discovered in HAProxy, a fast and reliable load balancing reverse proxy, which may result in denial of service, or bypass of access controls and routing rules via specially crafted requests.
Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host.
Jacob Champion discovered that libpq can leak memory contents after GSSAPI transport encryption initiation fails. A modified server, or an unauthenticated man-in-the-middle, can send a
This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358.
Several security vulnerabilities have been discovered in SDL2, the Simple DirectMedia Layer library. These vulnerabilities may allow an attacker to cause a denial of service or result in the execution of arbitrary code if malformed images or sound files are processed.
Multiple security vulnerabilities have been discovered in Wireshark, a network traffic analyzer. An attacker could cause a denial of service (infinite loop or application crash) via packet injection or a crafted capture file.
This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.
I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi,
Jan-Niklas Sohn, working with Trend Micro Zero Day Initiative, discovered a vulnerability in the X.Org X server. A potential use after free mighty result in local privilege escalation if
It was discovered that there were a number of issues in graphite-web, a tool provide realtime graphing of system statistics etc. A series of cross-site scripting (XSS) vulnerabilties existed that
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42826