Debian LTS Linux Distribution - Page 4.6
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
It was discovered that php-guzzlehttp-psr7, a PSR-7 message implementation, performed improper header parsing, which may lead to information disclosure or authorization bypass.
Even Rouault discovered that xerces-c, a validating XML parser library for C++, was vulnerable to integer overflow via crafted .xsd files, which can lead to out-of-bounds access.
Multiple vulnerabilities have been discovered in LibreOffice an office productivity software suite: CVE-2020-12801
Le Dinh Hai discovered that libspreadsheet-parseexcel-perl, a Perl module allowing information extraction from Excel spreadsheets, improperly sanitizes directives in dynamically evaluated code.
A reachable assertion issue has been discovered in tinyxml, a C++ XML parsing library, which could lead to denial of service via a crafted XML document with a '\0' located after whitespace.
An issue has been found in cjson, an ultralightweight JSON parser in ANSI C. The issue is related to a segmentation violation in function cJSON_InsertItemInArray().
Three issues have been found in libde265, an open H.265 video codec implementation. All issues are related to heap-buffer-overflow or global buffer overflow in different functions.
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing of signed PGP/MIME and SMIME emails.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape or clickjacking.
Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. CVE-2023-37457
Ansible a configuration management, deployment, and task execution system was affected by multiple vulnerabilities. CVE-2019-10206
Several vulnerabilities have been discovered in OpenSSH, an implementation of the SSH protocol suite. CVE-2021-41617
A Buffer Overflow vulnerability has been found in osslsigncode, a OpenSSL based Authenticode signing tool for PE/MSI/Java CAB files, which possibly allows an malicious attacker to execute arbitrary code when signing a crafted file.
Two security issues were found in Curl, an easy-to-use client-side URL transfer library and command line tool. Additionally, the command line tool does now:
Multiple security issues were discovered in SPIP, a content management system, which could lead to denial of service or information disclosure. For Debian 10 buster, this problem has been fixed in version
The initial fix for CVE-2023-6377 as applied in DLA 3686-1 did not fully fix the vulnerability. Updated packages correcting this issue including the upstream merged commit are now available.
Benoit Morgan, Paul Grosen, Thais Moreira Hamasaki, Ke Sun, Alyssa Milburn, Hisham Shafi, Nir Shlomovich, Tavis Ormandy, Daniel Moghimi, Josh Eads, Salman Qazi, Alexandra Sandulescu, Andy Nguyen, Eduardo Vela, Doug Kwan, and Kostik Shtoyk discovered that some Intel processors
It was discovered that there was a keyboard injection attack in Bluez, a set of services and tools for interacting with wireless Bluetooth devices.
It was discovered that there was a potential information disclosure vulnerability in HAProxy, a reverse proxy server used to load balance HTTP requests across multiple servers.
RabbitMQ is a multi-protocol messaging and streaming broker. The HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages by an authenticated user with sufficient credentials.
Sign up to get the latest security news affecting Linux and
open source delivered straight to your inbox
Powered By
Linux Security - Your source for Top Linux News, Advisories, HowTo's and Feature Release.