It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1.4.7-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.4.9-1. For the unstable distribution (sid), this […]
Risk High Date Discovered February 21, 2006 Description Apple Mac OS X is prone to an arbitrary command-execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file. Attackers can reportedly use Safari and Apple Mail as exploitation vectors for this vulnerability. Mac OS […]
Risk High Date Discovered May 10, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Risk Medium Date Discovered May 10, 2016 Description Microsoft Windows is prone to a local security-bypass vulnerability. A local attacker can leverage this issue to bypass certain security restrictions and perform unauthorized actions. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells. Allow only trusted individuals to have […]
Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2016-3710 Wei Xiao and Qinghao Tang of 360.cn Inc discovered an out-of-bounds read and write flaw in the QEMU VGA module. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the hosting QEMU process. CVE-2016-3712 […]
Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u2. We recommend that you upgrade your websvn packages.
Risk Medium Date Discovered May 10, 2016 Description The Microsoft .NET Framework is prone to an information-disclosure vulnerability. An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks. Recommendations Block external access at the network boundary, unless external parties require service. If global access […]
Risk Medium Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a security-bypass vulnerability. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content. An attacker can exploit this issue to execute arbitrary script code in the context of the user running the application. […]
Risk Medium Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to an information-disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks. Internet Explorer 10, and 11 are vulnerable. Technologies Affected Microsoft Internet Explorer 10 Microsoft Internet Explorer 11 Recommendations Run all software as a […]
Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]
Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]
Risk High Date Discovered May 10, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will […]
Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered a heap-based buffer overflow vulnerability in the zip_read_mac_metadata function in libarchive, a multi-format archive and compression library, which may lead to the execution of arbitrary code if a user or automated system is tricked into processing a specially crafted ZIP file. For the stable distribution (jessie), […]
Risk High Date Discovered May 10, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]
Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]
Risk High Date Discovered May 10, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can take advantage of this vulnerability to execute arbitrary code in the context of the currently logged-in user. Failed attacks […]
Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki’s use of imagemagick in the img plugin. For the stable distribution (jessie), this problem has been fixed in version 3.20141016.3. For the unstable distribution (sid), this problem has been fixed in version 3.20160506. We […]
It was discovered that libpam-sshauth, a PAM module to authenticate using an SSH server, does not correctly handle system users. In certain configurations an attacker can take advantage of this flaw to gain root privileges. For the stable distribution (jessie), this problem has been fixed in version 0.3.1-1+deb8u1. For the testing distribution (stretch), this problem […]
APPLE-SA-2016-05-03-1 Xcode 7.3.1 Subject: APPLE-SA-2016-05-03-1 Xcode 7.3.1 From: Apple Product Security <email@hidden> Date: Wed, 04 May 2016 10:36:15 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-05-03-1 Xcode 7.3.1 Xcode 7.3.1 is now available and addresses the following: Git Available for: OS X El Capitan v10.11 and later Impact: A remote attacker may be able to […]
Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to manage ASN.1 structures, does not correctly handle certain malformed DER certificates. A remote attacker can take advantage of this flaw to cause an application using the Libtasn1 library to hang, resulting in a denial of service. For the stable distribution (jessie), this problem has […]
Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service caused by a bug in the pioctl logic allowing a local user to overrun a kernel buffer with a single NUL byte. CVE-2016-2860 Peter Iannucci discovered that […]
Blake Burkhart discovered an arbitrary code execution flaw in Mercurial, a distributed version control system, when using the convert extension on Git repositories with specially crafted names. This flaw in particular affects automated code conversion services that allow arbitrary repository names. For the stable distribution (jessie), this problem has been fixed in version 3.1.2-2+deb8u3. For […]
Several security vulnerabilities were found in botan1.10, a C++ library which provides support for many common cryptographic operations, including encryption, authentication, X.509v3 certificates and CRLs. CVE-2015-5726 The BER decoder would crash due to reading from offset 0 of an empty vector if it encountered a BIT STRING which did not contain any data at all. […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1660 Atte Kettunen discovered an out-of-bounds write issue. CVE-2016-1661 Wadih Matar discovered a memory corruption issue. CVE-2016-1662 Rob Wu discovered a use-after-free issue related to extensions. CVE-2016-1663 A use-after-free issue was discovered in Blink’s bindings to V8. CVE-2016-1664 Wadih Matar discovered a way to spoof […]
Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-2105 Guido Vranken discovered that an overflow can occur in the function EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can supply a large amount of data. This could lead to a heap corruption. CVE-2016-2106 Guido Vranken discovered that an overflow can occur in […]
It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF file is opened. For the stable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u1. For the testing distribution (stretch), this problem has been fixed […]
Several vulnerabilities were discovered in tardiff, a tarball comparison tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-0857 Rainer Mueller and Florian Weimer discovered that tardiff is prone to shell command injections via shell meta-characters in filenames in tar files or via shell meta-characters in the tar filename itself. CVE-2015-0858 Florian Weimer […]
APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Thu, 28 Apr 2016 15:05:32 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-04-28-1 OS X: Flash Player plug-in blocked Due to security and stability issues in older versions, Apple has updated the web plug-in […]
Several vulnerabilities were discovered in Subversion, a version control system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2167 Daniel Shahaf and James McCoy discovered that an implementation error in the authentication against the Cyrus SASL library would permit a remote user to specify a realm string which is a prefix of the […]
Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. The vulnerabilities are addressed by upgrading PHP to the new upstream version 5.6.20, which includes additional bug fixes. Please refer to the upstream changelog for more information: For the stable distribution (jessie), these problems have been fixed in version […]
Multiple security issues have been found in Iceweasel, Debian’s version of the Mozilla Firefox web browser: Multiple memory safety errors and buffer overflows may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.8.0esr-1~deb7u1. For the stable distribution (jessie), these problems […]
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in breakouts of the Java sandbox, denial of service or information disclosure. For the stable distribution (jessie), these problems have been fixed in version 7u101-2.6.6-1~deb8u1. We recommend that you upgrade your openjdk-7 packages.
Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.49. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for further details: For the stable distribution (jessie), these problems have been fixed in version 5.5.49-0+deb8u1. We recommend that […]
Risk High Date Discovered November 11, 2014 Description Microsoft Windows is prone to a remote privilege-escalation vulnerability. An attacker can exploit this vulnerability to execute arbitrary code with elevated privileges. Technologies Affected Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 8 for 32-bit Systems Microsoft Windows 8 […]
Risk High Date Discovered September 30, 2003 Description Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. Attackers could exploit these issues to cause a denial of service or to execute arbitrary code. Recommendations Block external access at the network boundary, unless external parties require service. If global access isn’t needed, filter access […]
Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2011-5326 Kevin Ryde discovered that attempting to draw a 2×1 radi ellipse results in a floating point exception. CVE-2014-9771 It was discovered that an integer overflow could lead to invalid memory reads and unreasonably large memory allocations. CVE-2016-3993 Yuriy M. Kaminskiy discovered that drawing using […]
Hans Jerry Illikainen discovered that libgd2, a library for programmatic graphics creation and manipulation, suffers of a signedness vulnerability which may result in a heap overflow when processing specially crafted compressed gd2 data. A remote attacker can take advantage of this flaw to cause an application using the libgd2 library to crash, or potentially, to […]
CVE-2016-3960 (XSA-173) Ling Liu and Yihan Lian of the Cloud Security Team, Qihoo 360 discovered an integer overflow in the x86 shadow pagetable code. A HVM guest using shadow pagetables can cause the host to crash. A PV guest using shadow pagetables (i.e. being migrated) with PV superpages enabled (which is not the default) can […]
Régis Leroy from Makina Corpus discovered that varnish, a caching HTTP reverse proxy, is vulnerable to HTTP smuggling issues, potentially resulting in cache poisoning or bypassing of access control policies. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.2-2+deb7u2. We recommend that you upgrade your varnish packages.
Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections and bypass of the SecurityManager. For the oldstable distribution (wheezy), these problems have been fixed in version 7.0.28-4+deb7u4. This update also fixes CVE-2014-0119 and CVE-2014-0096. For the stable distribution (jessie), these […]
It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several vulnerabilities. CVE-2015-8836 A stack-based buffer overflow may allow attackers who can trick a user into mounting a crafted ISO 9660 file system to cause a denial of service (crash), or, potentially, execute arbitrary code. CVE-2015-8837 An […]
Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support is enabled and the sshd PAM configuration is configured to read userspecified environment variables and the UseLogin option is enabled, a local user may escalate her privileges to root. In Debian UseLogin is not enabled by default. For the oldstable distribution (wheezy), this problem has […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 A cross-site scripting issue was discovered in extension bindings. CVE-2016-1653 Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library. CVE-2016-1654 Atte Kettunen discovered an uninitialized memory read condition. CVE-2016-1655 Rob […]
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-5370 Jouni Knuutinen from Synopsys discovered flaws in the Samba DCE-RPC code which can lead to denial of service (crashes and high cpu consumption) and man-in-the-middle attacks. CVE-2016-2110 Stefan […]
Risk High Date Discovered April 12, 2016 Description Microsoft Windows is prone to a remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will result in a denial of service condition. Technologies Affected Microsoft .NET Framework 4.6 Microsoft .NET Framework […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote privilege-escalation vulnerability. An attacker can exploit this issue to gain elevated privileges. Successful exploits may aid in further attacks. Recommendations Block external access at the network boundary, unless external parties require service. Filter access to the affected computer at the […]
Risk High Date Discovered April 12, 2016 Description Microsoft Edge is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that might lead to memory leaks or denial of service. None of these security problems have a CVE number assigned. For the oldstable distribution (wheezy), this problem […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote code-execution vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft XML Core Services is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions. Technologies Affected Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk High Date Discovered April 12, 2016 Description Microsoft Office is prone to a remote memory-corruption vulnerability because it fails to properly handle objects in memory. An attacker can leverage this issue to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial of service conditions. […]
Risk Medium Date Discovered April 12, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Risk High Date Discovered April 12, 2016 Description Microsoft Windows is prone to a memory-corruption vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions. Technologies Affected Microsoft .NET Framework 3.0 SP2 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5.1 Microsoft Live […]
Risk Medium Date Discovered April 12, 2016 Description Microsoft Windows is prone to a local privilege-escalation vulnerability that occurs in the Windows kernel. A local attacker can exploit this issue to execute arbitrary code in kernel mode with elevated privileges. Recommendations Permit local access for trusted individuals only. Where possible, use restricted environments and restricted […]
Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.6.4-1+deb7u2. This update also fixes CVE-2015-7801, which […]
Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark Striemer discovered that some user-supplied redirect URLs containing basic authentication credentials are incorrectly handled, potentially allowing a remote attacker to perform a malicious redirect or a cross-site scripting attack. CVE-2016-2513 Sjoerd […]
Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of these flaws to perform cross-site scripting, header injection or denial of service attacks. For the stable distribution (jessie), these problems have been fixed in version 0.10.2.git2.0.1-3+deb8u1. For the testing distribution (stretch), these […]
High-Tech Bridge Security Research Lab discovered that Roundcube, a webmail client, contained a path traversal vulnerability. This flaw could be exploited by an attacker to access sensitive files on the server, or even execute arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 0.7.2-9+deb7u2. For the testing (stretch) and unstable […]
Several vulnerabilities have been discovered in Mercurial, a distributed version control system. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2016-3068 Blake Burkhart discovered that Mercurial allows URLs for Git subrepositories that could result in arbitrary code execution on clone. CVE-2016-3069 Blake Burkhart discovered that Mercurial allows arbitrary code execution when converting Git […]
Emmanuel Thome discovered that missing sanitising in the oarsh command of OAR, a software used to manage jobs and resources of HPC clusters, could result in privilege escalation. For the oldstable distribution (wheezy), this problem has been fixed in version 2.5.2-3+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.5.4-2+deb8u1. For […]
Risk High Date Discovered March 8, 2016 Description Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability. Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted web page. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed […]
Marcin Noga discovered an integer underflow in Lhasa, a lzh archive decompressor, which might result in the execution of arbitrary code if a malformed archive is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.0.7-2+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.2.0+git3fe46-1+deb8u1. For the […]
Randell Jesup and the Firefox team discovered that srtp, Cisco’s reference implementation of the Secure Real-time Transport Protocol (SRTP), does not properly handle RTP header CSRC count and extension header length. A remote attacker can exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service. For the oldstable distribution […]
APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 Subject: APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 From: Apple Product Security <email@hidden> Date: Thu, 31 Mar 2016 14:14:32 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-31-1 iBooks Author 2.4.1 iBooks Author 2.4.1 is now available and addresses the following: iBooks Author Available for: OS X Yosemite v10.10 or later Impact: Parsing a maliciously […]
It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. For the oldstable distribution (wheezy), this problem has been fixed in version 1.2.9-5+deb7u2. We recommend that you upgrade your libstruts1.2-java packages.
Several vulnerabilities were discovered in imlib2, an image manipulation library. CVE-2014-9762 A segmentation fault could occur when opening GIFs without a colormap. CVE-2014-9763 Several divisions by zero, resulting in a program crash, could occur when handling PNM files. CVE-2014-9764 A segmentation fault could occur when opening GIFs with feh. For the oldstable distribution (wheezy), these […]
Several vulnerabilities were discovered in libebml, a library for manipulating Extensible Binary Meta Language files. CVE-2015-8789 Context-dependent attackers could trigger a use-after-free vulnerability by providing a maliciously crafted EBML document. CVE-2015-8790 Context-dependent attackers could obtain sensitive information from the process’ heap memory by using a maliciously crafted UTF-8 string. CVE-2015-8791 Context-dependent attackers could obtain sensitive […]
Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy which might result in the execution of arbitrary code. For the stable distribution (jessie), this problem has been fixed in version 4.2.0-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 4.3.4-2. For the unstable distribution (sid), this problem has been […]
Risk Medium Date Discovered August 12, 2008 Description Microsoft Windows Messenger is prone to an information-disclosure vulnerability. An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious HTML page. Successfully exploiting this issue allows remote attackers to obtain sensitive information that may aid in further attacks. Technologies Affected Microsoft Windows […]
Risk High Date Discovered June 17, 2008 Description Microsoft Word is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue by enticing a victim to open and interact with malicious Word files. Successfully exploiting this issue will corrupt memory and crash the application. Given the nature of this issue, attackers may also […]
APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Subject: APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked From: Apple Product Security <email@hidden> Date: Mon, 28 Mar 2016 13:20:04 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-28-1 OS X: Flash Player plug-in blocked Due to security issues in older versions, Apple has updated the web plug-in blocking mechanism […]
Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer reserved for MPLS labels in an OVS internal data structure. A remote attacker can take advantage of this flaw to cause a denial of service, or […]
Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP client, which may result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1:3.2.3-11+deb7u1. We recommend that you upgrade your dhcpcd packages.
Risk High Date Discovered February 5, 2015 Description Adobe Flash Player is prone to multiple unspecified security vulnerabilities. Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed attacks may cause denial-of-service conditions. Recommendations Run all software as a nonprivileged user with minimal access rights. […]
Kostya Kortchinsky discovered a stack-based buffer overflow vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP routing daemon. A remote attacker can exploit this flaw to cause a denial of service (daemon crash), or potentially, execution of arbitrary code, if bgpd is configured with BGP peers enabled for VPNv4. For the oldstable […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1646 Wen Xu discovered an out-of-bounds read issue in the v8 library. CVE-2016-1647 A use-after-free issue was discovered. CVE-2016-1648 A use-after-free issue was discovered in the handling of extensions. CVE-2016-1649 lokihardt discovered a buffer overflow issue in the Almost Native Graphics Layer Engine (ANGLE) library. […]
Multiple security vulnerabilities have been fixed in the Tomcat servlet and JSP engine, which may result on bypass of security manager restrictions, information disclosure, denial of service or session fixation. For the oldstable distribution (wheezy), these problems have been fixed in version 6.0.45+dfsg-1~deb7u1. We recommend that you upgrade your tomcat6 packages.
Multiple vulnerabilities have been found in Redmine, a project management web application, which may result in information disclosure. For the stable distribution (jessie), these problems have been fixed in version 3.0~20140825-8~deb8u2. For the testing distribution (stretch), these problems have been fixed in version 3.2.0-1. For the unstable distribution (sid), these problems have been fixed in […]
Stefan Sperling discovered that pidgin-otr, a Pidgin plugin implementing Off-The-Record messaging, contained a use-after-free bug. This could be used by a malicious remote user to intentionally crash the application, thus causing a denial-of-service. For the stable distribution (jessie), this problem has been fixed in version 4.0.1-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this […]
It was discovered that libmatroska, an extensible open standard audio/video container format, incorrectly processed EBML lacing. By providing maliciously crafted input, an attacker could use this flaw to force some leakage of information located in the process heap memory. For the oldstable distribution (wheezy), this problem has been fixed in version 1.3.0-2+deb7u1. For the stable […]
It was discovered that inspircd, an IRC daemon, incorrectly handled PTR lookups of connecting users. This flaw allowed a remote attacker to crash the application by setting up malformed DNS records, thus causing a denial-of-service, For the oldstable distribution (wheezy), this problem has been fixed in version 2.0.5-1+deb7u2. For the stable distribution (jessie), this problem […]
Vincent LE GARREC discovered an integer overflow in pixman, a pixel-manipulation library for X and cairo. A remote attacker can exploit this flaw to cause an application using the pixman library to crash, or potentially, to execute arbitrary code with the privileges of the user running the application. For the oldstable distribution (wheezy), this problem […]
It was discovered that the ActiveMQ Java message broker performs unsafe deserialisation. For additional information, please refer to the upstream advisory at http://activemq.apache.org/security-advisories.data/CVE-2015-5254-announcement.txt. For the oldstable distribution (wheezy), this problem has been fixed in version 5.6.0+dfsg-1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 5.6.0+dfsg1-4+deb8u2. For the testing distribution (stretch), this […]
This update disables the Graphite font shaping library in Iceweasel, Debian’s version of the Mozilla Firefox web browser. For the oldstable distribution (wheezy), this problem has been fixed in version 38.7.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.7.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in […]
APPLE-SA-2016-03-21-7 OS X Server 5.1 Subject: APPLE-SA-2016-03-21-7 OS X Server 5.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:38 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-7 OS X Server 5.1 OS X Server 5.1 is now available and addresses the following: Server App Available for: OS X Yosemite v10.10.5 and later […]
APPLE-SA-2016-03-21-6 Safari 9.1 Subject: APPLE-SA-2016-03-21-6 Safari 9.1 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:54:10 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-6 Safari 9.1 Safari 9.1 is now available and addresses the following: libxml2 Available for: OS X Mavericks v10.9.5, OS X Yosemite v10.10.5, OS X El Capitan v10.11 to v10.11.3 […]
APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 Subject: APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:54 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 OS X El Capitan 10.11.4 and […]
APPLE-SA-2016-03-21-4 Xcode 7.3 Subject: APPLE-SA-2016-03-21-4 Xcode 7.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:29 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-4 Xcode 7.3 Xcode 7.3 is now available and addresses the following: otool Available for: OS X El Capitan v10.11 and later Impact: A local attacker may be able to […]
APPLE-SA-2016-03-21-3 tvOS 9.2 Subject: APPLE-SA-2016-03-21-3 tvOS 9.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:53:12 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-3 tvOS 9.2 tvOS 9.2 is now available and addresses the following: FontParser Available for: Apple TV (4th generation) Impact: Opening a maliciously crafted PDF file may lead to an […]
APPLE-SA-2016-03-21-2 watchOS 2.2 Subject: APPLE-SA-2016-03-21-2 watchOS 2.2 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:51:14 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-2 watchOS 2.2 watchOS 2.2 is now available and addresses the following: Disk Images Available for: Apple Watch Sport, Apple Watch, Apple Watch Edition, and Apple Watch Hermes Impact: An […]
APPLE-SA-2016-03-21-1 iOS 9.3 Subject: APPLE-SA-2016-03-21-1 iOS 9.3 From: Apple Product Security <email@hidden> Date: Mon, 21 Mar 2016 17:49:31 -0700 —–BEGIN PGP SIGNED MESSAGE—– Hash: SHA512 APPLE-SA-2016-03-21-1 iOS 9.3 iOS 9.3 is now available and addresses the following: AppleUSBNetworking Available for: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later Impact: […]
Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses. A remote HTTP server can exploit this flaw to cause a denial of service (assertion failure and daemon exit). For the oldstable distribution (wheezy), this problem has been fixed in […]
Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.7.0-1~deb7u1. For the […]
Lael Cellier discovered two buffer overflow vulnerabilities in git, a fast, scalable, distributed revision control system, which could be exploited for remote execution of arbitrary code. For the oldstable distribution (wheezy), these problems have been fixed in version 1:1.7.10.4-1+wheezy3. For the stable distribution (jessie), these problems have been fixed in version 1:2.1.4-2.1+deb8u2. For the unstable […]
