|
King of Glory Lutheran Church
Do a presentation at NTLUG.
What is the Linux Installation Project?
Real companies using Linux!
Not just for business anymore.
Providing ready to run platforms on Linux
|
<< Mandriva | Distributions | Gentoo >>
Community
Support
|
Debian Planet
|
Debian Security Notices
- DSA-2384 cacti - several vulnerabilities
Several vulnerabilities have been discovered in Cacti, a graphing toolfor monitoring data. Multiple cross site scripting issues allow remoteattackers to inject arbitrary web script or HTML. An SQL injectionvulnerability allows remote attackers to execute arbitrary SQL commands.
- DSA-2403 php5 - code injection
Stefan Esser discovered that the implementation of the max_input_varsconfiguration variable in a recent PHP security update was flawed suchthat it allows remote attackers to crash PHP or potentially executecode.
- DSA-2400 iceweasel - several vulnerabilities
Several vulnerabilities have been discovered in Iceweasel, a web browserbased on Firefox. The included XULRunner library provides renderingservices for several other applications included in Debian.
- DSA-2399 php5 - several vulnerabilities
Several vulnerabilities have been discovered in PHP, the web scriptinglanguage. The Common Vulnerabilities and Exposures project identifiesthe following issues:
- DSA-2398 curl - several vulnerabilities
Several vulnerabilities have been discovered in cURL, an URL transferlibrary. The Common Vulnerabilities and Exposures project identifies thefollowing problems:
- DSA-2396 qemu-kvm - buffer underflow
Nicolae Mogoraenu discovered a heap overflow in the emulated e1000enetwork interface card of KVM, a solution for full virtualization onx86 hardware, which could result in denial of service or privilegeescalation.
- DSA-2395 wireshark - buffer underflow
Laurent Butti discovered a buffer underflow in the LANalyzer dissectorof the Wireshark network traffic analyzer, which could lead to theexecution of arbitrary code (CVE-2012-0068).
- DSA-2393 bip - buffer overflow
Julien Tinnes reported a buffer overflow in the Bip multiuser IRC proxywhich may allow arbitrary code execution by remote users.
- DSA-2392 openssl - out-of-bounds read
Antonio Martin discovered a denial-of-service vulnerability inOpenSSL, an implementation of TLS and related protocols. A maliciousclient can cause the DTLS server implementation to crash. Regular,TCP-based TLS is not affected by this issue.
- DSA-2301 rails - several vulnerabilities
Several vulnerabilities have been discovered in Rails, the Ruby webapplication framework. The Common Vulnerabilities and Exposures projectidentifies the following problems:
- DSA-2391 phpmyadmin - several vulnerabilities
Several vulnerabilities have been discovered in phpMyAdmin, a toolto administer MySQL over the web. The Common Vulnerabilities andExposures project identifies the following problems:
- DSA-2390 openssl - several vulnerabilities
Several vulnerabilities were discovered in OpenSSL, an implementationof TLS and related protocols. The Common Vulnerabilities andExposures project identifies the following vulnerabilities:
- DSA-2388 t1lib - several vulnerabilities
Several vulnerabilities were discovered in t1lib, a Postscript Type 1font rasterizer library, some of which might lead to code executionthrough the opening of files embedding bad fonts.
- DSA-2386 openttd - several vulnerabilities
Several vulnerabilities have been discovered in OpenTTD, a transportbusiness simulation game. Multiple buffer overflows and off-by-oneerrors allow remote attackers to cause denial of service.
- DSA-2385 pdns - packet loop
Ray Morris discovered that the PowerDNS authoritative server respondsto response packets. An attacker who can spoof the source address ofIP packets can cause an endless packet loop between a PowerDNSauthoritative server and another DNS server, leading to a denial ofservice.
- DSA-2383 super - buffer overflow
Robert Luberda discovered a buffer overflow in the syslog logging code ofSuper, a tool to execute scripts (or other commands) as if they were root.The default Debian configuration is not affected.
|