Debian LTS Essential and Critical Security Patch Updates - Page 5
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.
Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.
Vulnerabilities were found in Perl's CPAN.pm, which could lead CPAN clients to install malicious modules. CVE-2020-16156
Two issues have been found in asterisk, an Open Source Private Branch Exchange.
It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform.
It was discovered that there was an arbitrary object deserialization vulnerability in php-horde-turba, an address book component for the Horde groupware suite.
The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For Debian 11 bullseye, these problems have been fixed in version
Two vulnerabilities have been fixed in python-cryptography, a cryptography library for the Python interpreter. CVE-2023-23931
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in execution of arbitrary code, erroneous parsing of invalid URLs or multipart form data, configuration setting bypass, or log pollution.
It was discovered that there was a configuration issue in libapache-mod-jk, an Apache web server module used to forward requests from Apache to Tomcat using the AJP protocol.
A vulnerability has been detected in the Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances.
Reportlab allowed attackers to execute arbitrary code (RCE) via supplying a crafted PDF file. For Debian 11 bullseye, this problem has been fixed in version
Various file formats are based on the zip file format. In cases of corruption of the underlying zip's central directory, LibreOffice offers a "repair mode" which will attempt to recover the zip file structure by scanning for secondary local
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version
Damien Schaeffer discovered a use-after-free in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For Debian 11 bullseye, this problem has been fixed in version
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.