Two security issues (cross-site scripting and directory traversal) were found in Rack, an interface for developing web applications in Ruby. For the oldstable distribution (bookworm), these problems have been fixed in version 2.2.22-0+deb12u1. For the stable distribution (trixie), these problems[…]
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 1:140.9.0esr-1~deb12u1. For the stable distribution (trixie), these problems have[…]
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure, denial of service or privilege escalation. For the oldstable distribution (bookworm), these problems have[…]
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.164-1~deb12u1.
Kazuma Matsumoto discovered an integer overflow bug in the EAP-TTLS plugin of strongSwan, an IKE/IPsec suite. The EAP-TTLS plugin doesn't check the length field in the header of attribute-value pairs (AVPs) tunneled in EAP-TTLS, which can cause an integer underflow[…]
Several vulnerabilities were discovered in libyaml-syck-perl, a Perl module providing a fast, lightweight YAML loader and dumper, which may result in denial of service and potentially arbitrary code execution. For the oldstable distribution (bookworm), this problem has been fixed in[…]
Jul Blobul discovered that SPIP, a website engine for publishing, is prone to a privilege escalation vulnerability. For the stable distribution (trixie), this problem has been fixed in version 4.4.13+dfsg-0+deb13u1. We recommend that you upgrade your spip packages.
Louis Moureaux discovered that incorrect packet processing in the game server of Freeciv, a free clone of the turn based strategy game Civilization, could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in[…]
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.153-1~deb12u1.
The Qualys Threat Research Unit (TRU) discovered a local privilege escalation vulnerability in snapd, a daemon and tooling that enable snap packages. Details can be found in the Qualys advisory at https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-systemd-tmpfiles.txt For the oldstable distribution (bookworm), this problem has[…]
Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to symlink races, information leaks, denial of service and potentially arbitrary code execution. For the stable distribution (trixie), these problems[…]
It was discovered that an integer overflow in the Freetype font engine could result in information disclosure or denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version[…]
An integer overflow was discovered in the RIFF parser of the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the oldstable distribution (bookworm),[…]
Multiple vulnerabilities were discovered in Node.js, which could result in denial of service or information disclosure or bypass of file restrictions. For the stable distribution (trixie), these problems have been fixed in version 20.19.2+dfsg-1+deb13u1.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. Google is aware that exploits for both CVEs exist in the wild. For the oldstable distribution (bookworm), these problems[…]
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.71-1~deb12u1.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys[…]
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. The Qualys Threat Research Unit (TRU) discovered several vulnerabilities in Apparmor. Details can be found in the Qualys[…]
It was discovered that the parse_options_header() function of multipart, a Python multipart/form-data parser was susceptible to denial of service via malformed request headers or multipart/form-data streams. For the stable distribution (trixie), this problem has been fixed in version 1.2.1-2+deb13u1.
Letzte Änderung am Freitag, 01 Januar 2016 20:59