Debian LTS Essential and Critical Security Patch Updates - Page 43
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
There were a couple of secuity issues found in sysstat, system performance tools for Linux, which are as follows: CVE-2019-16167
Three vulnerabilities have been fixed that could, under rare circumstances, lead to remotely exploitable DoS vulnerabilities in software using exiv2 for meta-data extraction.
Two vulnerabilities were found in the Xkb extension of the X.org X server, which could result in denial of service or possibly privilege escalation if the X server is running privileged.
It was discovered that libjettison-java, a collection of StAX parsers and writers for JSON, was vulnerable to a denial-of-service attack, if the attacker provided untrusted XML or JSON data.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42799
For Debian 10 buster, these problems have been fixed in version 2:8.1.0875-5+deb10u3. We recommend that you upgrade your vim packages.
It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.
It was discovered that there was a information disclosure utility in sudo, a tool used to provide limited superuser privileges to specific users.
It was discovered that scciclient did not verify server TLS certificates when making requests. For Debian 10 buster, this problem has been fixed in version
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
This is a routine update of the distro-info-data database for Debian LTS users. It includes a correction to some historical data, and adds Ubuntu 23.04, Lunar Lobster.
Several security vulnerabilities were discovered in clickhouse, a column-oriented database system. The vulnerabilities require authentication, but can be triggered by any user
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Nicky Mouha discovered a buffer overflow in '_sha3', the SHA-3 hashing function module used by 'hashlib' in Python 3.7. While the attacks require a large volume of data, they could potentially result
Nicky Mouha discovered a buffer overflow in 'sha3', a Python library for the SHA-3 hashing functions. For Debian 10 buster, this problem has been fixed in version
It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version
It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For Debian 10 buster, these problems have been fixed in version
An issue has been found in openvswitch, a software-based, Ethernet virtual switch.
An issue has been found in ncurses, a collection of shared libraries for terminal handling. This issue is about an out-of-bounds read in convert_strings in the