Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

King of Glory Lutheran Church

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

<< Mandriva | Distributions | Gentoo >>


Community

Support

Debian Planet

Debian Security Notices

  • DSA-2384 cacti - several vulnerabilities
    Several vulnerabilities have been discovered in Cacti, a graphing toolfor monitoring data. Multiple cross site scripting issues allow remoteattackers to inject arbitrary web script or HTML. An SQL injectionvulnerability allows remote attackers to execute arbitrary SQL commands.


  • DSA-2403 php5 - code injection
    Stefan Esser discovered that the implementation of the max_input_varsconfiguration variable in a recent PHP security update was flawed suchthat it allows remote attackers to crash PHP or potentially executecode.




  • DSA-2400 iceweasel - several vulnerabilities
    Several vulnerabilities have been discovered in Iceweasel, a web browserbased on Firefox. The included XULRunner library provides renderingservices for several other applications included in Debian.


  • DSA-2399 php5 - several vulnerabilities
    Several vulnerabilities have been discovered in PHP, the web scriptinglanguage. The Common Vulnerabilities and Exposures project identifiesthe following issues:


  • DSA-2398 curl - several vulnerabilities
    Several vulnerabilities have been discovered in cURL, an URL transferlibrary. The Common Vulnerabilities and Exposures project identifies thefollowing problems:



  • DSA-2396 qemu-kvm - buffer underflow
    Nicolae Mogoraenu discovered a heap overflow in the emulated e1000enetwork interface card of KVM, a solution for full virtualization onx86 hardware, which could result in denial of service or privilegeescalation.


  • DSA-2395 wireshark - buffer underflow
    Laurent Butti discovered a buffer underflow in the LANalyzer dissectorof the Wireshark network traffic analyzer, which could lead to theexecution of arbitrary code (CVE-2012-0068).



  • DSA-2393 bip - buffer overflow
    Julien Tinnes reported a buffer overflow in the Bip multiuser IRC proxywhich may allow arbitrary code execution by remote users.


  • DSA-2392 openssl - out-of-bounds read
    Antonio Martin discovered a denial-of-service vulnerability inOpenSSL, an implementation of TLS and related protocols. A maliciousclient can cause the DTLS server implementation to crash. Regular,TCP-based TLS is not affected by this issue.


  • DSA-2301 rails - several vulnerabilities
    Several vulnerabilities have been discovered in Rails, the Ruby webapplication framework. The Common Vulnerabilities and Exposures projectidentifies the following problems:


  • DSA-2391 phpmyadmin - several vulnerabilities
    Several vulnerabilities have been discovered in phpMyAdmin, a toolto administer MySQL over the web. The Common Vulnerabilities andExposures project identifies the following problems:


  • DSA-2390 openssl - several vulnerabilities
    Several vulnerabilities were discovered in OpenSSL, an implementationof TLS and related protocols. The Common Vulnerabilities andExposures project identifies the following vulnerabilities:



  • DSA-2388 t1lib - several vulnerabilities
    Several vulnerabilities were discovered in t1lib, a Postscript Type 1font rasterizer library, some of which might lead to code executionthrough the opening of files embedding bad fonts.



  • DSA-2386 openttd - several vulnerabilities
    Several vulnerabilities have been discovered in OpenTTD, a transportbusiness simulation game. Multiple buffer overflows and off-by-oneerrors allow remote attackers to cause denial of service.


  • DSA-2385 pdns - packet loop
    Ray Morris discovered that the PowerDNS authoritative server respondsto response packets. An attacker who can spoof the source address ofIP packets can cause an endless packet loop between a PowerDNSauthoritative server and another DNS server, leading to a denial ofservice.


  • DSA-2383 super - buffer overflow
    Robert Luberda discovered a buffer overflow in the syslog logging code ofSuper, a tool to execute scripts (or other commands) as if they were root.The default Debian configuration is not affected.




Debian Forum at linuxquestions.org

Page last modified on September 14, 2006, at 12:07 AM