Debian LTS Essential and Critical Security Patch Updates - Page 46
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
An issue has been found in libhttp-daemon-perl, a simple http server class. Due to insufficient Content-Length: handling in HTTP-header an attacker
An issue has been found in libsndfile, a library for reading/writing audio files.
Two issues have been found in libvncserver, a library to write one's own VNC server.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-32886
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. Debian follows the Thunderbird upstream releases. Support for the 91.x
Two security issues were discovered in dovecot: IMAP and POP3 email server. CVE-2021-33515
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, CSP bypass or session fixation.
Several security vulnerabilities have been discovered in Poppler, a PDF rendering library, that could lead to denial of service or possibly other unspecified impact when processing maliciously crafted documents.
Rhodri James discovered a heap use-after-free vulnerability in the doContent function in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a
Sandipan Roy discovered two vulnerabilities in InfoZIP's unzip program, a de-archiver for .zip files, which could result in denial of service or potentially the execution of arbitrary code.
Several security vulnerabilities were discovered in mediawiki, a website engine for collaborative work. Insufficiently escaped input text may allow a malicious user to perform cross-site-scripting (XSS) attacks.
It was found that Mako, a Python template library, was vulnerable to a denial of service attack via crafted regular expressions. For Debian 10 buster, this problem has been fixed in version
Maher Azzouzi found a local root escalation vulnerability in Enlightenment, an X11 window manager. For Debian 10 buster, this problem has been fixed in version
Multiple file parsing vulnerabilities have been fixed in libraw. They are concerned with the dng and x3f formats. CVE-2020-35530
Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.3.36. Please see the MariaDB 10.3 Release Notes for further details:
This update fixes bzdiff when using it with two compressed files. It also includes a fix to support large files on 32 bit systems. For Debian 10 buster, this problem has been fixed in version
An issue has been found in mod-wsgi, a Python WSGI adapter module for Apache. A request from an untrusted proxy does not remove the X-Client-IP header and thus allowing this header to be passed to the target WSGI application.
It was found that GLib, a general-purpose portable utility library, could be used to print partial contents from arbitrary files. This could be exploited from setuid binaries linking to GLib for information disclosure of files with a specific format.
The security update announced as DLA 3093-1 which included fix for CVE-2022-32224 caused a regression due to incompatibility with ruby 2.5 version. We have dropped aforementioned fix. Updated rails packages are now available.
It was found that authenticated users could trigger a fault in Nova, a cloud computing fabric controller, to cause information leak. In addition, this update includes some fixes for volume live migration,