«
Expand/Collapse
1246 items tagged "debian"
Related tags:
buffer overflow [+],
rendering services [+],
png library [+],
web scripting language [+],
web content management [+],
tyni [+],
thunderbird mail [+],
ogg vorbis [+],
niko tyni [+],
network interface card [+],
matthew hall [+],
mail news [+],
centralized configuration [+],
based buffer overflow [+],
image manipulation [+],
debian security [+],
linux kernel [+],
internet suite [+],
westwood studios [+],
web content management system [+],
vervier [+],
untrusted sources [+],
unicode library [+],
truetype fonts [+],
transfer library [+],
torcs [+],
tomas hoger [+],
stefan esser [+],
sql database [+],
sony atrac3 [+],
server implementations [+],
security vulnerabilities [+],
security advisory [+],
ruby [+],
resume builder [+],
resource limit [+],
qemu [+],
python interface [+],
postgresql database server [+],
perl interface [+],
perl dbi [+],
performance improvements [+],
pam library [+],
pam [+],
nsv files [+],
niels heinen [+],
mozilla thunderbird [+],
memory region [+],
memory accesses [+],
max input [+],
matthew daley [+],
mateusz jurczyk [+],
markus vervier [+],
mailing list manager [+],
jurczyk [+],
javascript statements [+],
java virtual machine [+],
java implementation [+],
jabber client [+],
integer overflow [+],
image manipulation program [+],
html options [+],
host list [+],
helmut hummel [+],
hashing algorithm [+],
gnu image manipulation program [+],
gnu image manipulation [+],
flexible interface [+],
external entities [+],
excessive resources [+],
example scripts [+],
encryption modes [+],
dominic hargreaves [+],
doc [+],
dns query [+],
denial of service attacks [+],
database management system [+],
dai [+],
cvs server [+],
cvs client [+],
cves [+],
course management system [+],
content management framework [+],
configuration management tool [+],
configuration management system [+],
command line tool [+],
command line parameters [+],
code execution [+],
cdf format [+],
buffer overflows [+],
asterisk pbx [+],
archives management [+],
arbitrary html [+],
arbitrary code execution [+],
application crashes [+],
application crash [+],
apple mjpeg b [+],
apache httpd server [+],
xml entities [+],
vulnerabilitites [+],
tavis ormandy [+],
ssh daemon [+],
security checks [+],
rdf parser [+],
quake 3 [+],
network traffic analyzer [+],
mime messages [+],
memory leak [+],
laurent butti [+],
ivan nestlerode [+],
information disclosure [+],
google [+],
dave love [+],
danny fullerton [+],
butti [+],
bugtraq [+],
security [+],
advisory [+],
linux security [+],
denial of service [+],
status requests [+],
sql toolkit [+],
script parameters [+],
pidgin [+],
oracle java [+],
nicola fioravanti [+],
linux [+],
jsp engine [+],
input parameters [+],
formatted message [+],
folder names [+],
emacs interface [+],
debian linux [+],
zurich,
zone transfer,
zombie process,
ziv,
zephyr,
zabrocki,
yang dingning,
xml security,
xml input,
xen virtual machine,
x.org,
x force,
wouter coekaerts,
witold baryluk,
william grant,
willem pinckaers,
wikiwiki,
webmail application,
weblog manager,
webdav server,
web script,
web proxy cache,
web proxy,
web frontend,
web control panel,
web based irc client,
web based irc,
web application framework,
web administration tool,
watson,
vulnerability research,
vulnerability,
vulnerabilities,
vp5,
volker lendecke,
vnc server,
vladimir kolesnikov,
vincent,
vasiliy kulikov,
var,
valid numbers,
user mode linux,
user,
unprivileged users,
unix domain socket,
unexpected source,
undefined symbol,
udp packet,
ubuntu,
txt,
trouble ticket system,
tor,
tomcat servlet,
tls server,
time passwords,
tim zingelmann,
tiff library,
tiff files,
tiff,
ticket request,
thin client,
terminal multiplexer,
temporary file,
template parameter,
target user,
tarball,
system filter,
symlink attack,
svq1,
subject alternate names,
string routines,
steve dispensa,
stefan goebel,
stack overflow,
stable point,
stable distribution,
sslv3,
sql injection,
sql commands,
space tools,
source component,
sound server,
software distributors,
socks,
snmp discovery,
sklenar,
signature verification,
shell escape,
shell environment variables,
shell commands,
shell,
setuid program,
service vulnerability,
service server,
service,
server implementation,
server extension,
server crashes,
server crash,
server,
sensitive operation,
security library,
security credentials,
security compromise,
sebastian krahmer,
scsi target,
scalable mail,
sanitizing,
sanitization,
samba web administration tool,
runtime environment,
rsa keys,
rootkit,
root privileges,
root group,
root ca,
rogue server,
rocco calvi,
robert luberda,
riku hietamaki,
richard silverman,
ricardo narvaja,
revision control system,
research purposes,
request tracker,
renegotiation,
red hat inc,
recursive dns queries,
ray morris,
raphael hertzog,
query execution,
qt4,
python web,
python bindings,
protocol suite,
programming error,
proftpd,
privilege escalation vulnerability,
privacy tool,
print servers,
postscript type,
postfix,
popular library,
png image,
png files,
player server,
platform management,
pickle data,
philip martin,
phil oester,
petr sklenar,
pdf,
pcmcia card,
pc directory,
paul mcmillan,
paul belanger,
passwd entries,
paris,
pam module,
package management system,
package content,
package,
p. tumenas,
overlay network,
oprofile,
openssl toolkit,
openssl libraries,
openoffice org office suite,
open ticket,
open source document management,
office productivity suite,
object persistence,
null pointer dereference,
null pointer,
nis,
nicolas gregoire,
networking system,
network security service,
network protocol analyzer,
nelson elhage,
neel mehta,
nav,
nahuel,
mysql database server,
multiple,
multimedia libraries,
morphological analysis,
moritz naumann,
modplug tracker,
mips architecture,
minimal memory,
minh,
milter,
mike oconnor,
microsoft word doc,
michael brooks,
meta characters,
message bus,
memory structures,
memory footprint,
memory corruption,
memory access,
md5 hashes,
matthew nicholson,
mathias svensson,
martin rex,
marsh ray,
mark martinec,
mark kaplan,
marius tomaschewski,
marco kampmann,
manager interface,
malicious client,
mail transport agent,
mail transfer agent,
mail system,
mail senders,
mail headers,
mail delivery agent,
mail client,
mail,
mahara,
mac check,
mac,
m. lucinskij,
lwp file,
lua script,
lotus word,
logwatch,
logrotate,
logging code,
log,
location object,
local security,
local privilege escalation,
load path,
linux scsi,
linux printing,
lintian,
libsndfile,
library implementation,
leo iannacone,
lenny host,
lenny,
leadbeater,
ldap servers,
l. weichselbaum,
kulikov,
krahmer,
kolesnikov,
kolab cyrus imap,
kolab,
kohlar,
kevin finisterre,
kevin chen,
kernel module,
kernel,
kern,
kerberos support,
kerberos 5,
kde desktop environment,
kde core libraries,
kampmann,
jpeg 2000,
jon larimer,
joel voss,
jesse ruderman,
javaserver faces,
javascript engine,
jared allar,
jamie strandboge,
jacob appelbaum,
jabber server,
ivan shmakov,
isc dhcp,
isa devices,
isa,
irc services,
irc proxy,
irc bouncer,
invalid pointer,
internet storage,
interface library,
interface event,
interactive mapping applications,
intelligent platform,
instrumentation system,
instant messaging server,
insecure settings,
input validation,
input strings,
information security group,
information leak,
ike,
iceweasel,
ian graham,
hypertext preprocessor,
huzaifa sidhpurwala,
https certificates,
httpd web server,
hp linux,
helin,
heap corruption,
handshake message,
hammond,
hacks,
groupware server,
gnu linux,
gnu libc,
gnu c library,
gnome desktop,
git,
gabble,
ftp daemon,
format tiff,
fontforge,
font library,
font files,
font editor,
florian kohlar,
file descriptor,
ffmpeg,
ferdinand smit,
federated authentication,
fastcgi applications,
exim,
excessive cpu usage,
exact impact,
eth zurich,
escape,
entrust inc,
engine library,
endless loop,
encryption support,
encrypted messages,
empty strings,
emmanuel bouillon,
elliptic curves,
electronic portfolio,
dynamic loader,
dynamic dns updates,
dylan simon,
dsa,
dominik george,
dokuwiki,
document viewer,
document management system,
dns zones,
dns root,
dns protocol,
dns configurations,
dns,
disclosure issues,
directory traversal vulnerability,
digital signature,
diginotar,
digicert sdn bhd,
dictionary files,
dhcp,
dhclient,
device server,
desktop,
denis courmont,
denial of service attack,
denial,
default stylesheet,
default mail,
default debian,
debian version,
debian package management,
debian package,
debian gnu,
deason,
deallocation,
david zych,
david wheeler,
david maciejak,
david leadbeater,
database utility,
data image,
daniel danner,
dan rosenberg,
daemon,
d. fabian,
cyrus imapd,
cyrus imap server,
cyrus imap,
csrf,
cryptographic libraries,
crypto library,
cross site scripting,
cross platform c,
cronjob,
creation vulnerability,
core functionality,
conversion library,
conversion functions,
confirmation messages,
configuration management solution,
configuration,
compression utilities,
common unix printing system,
common unix printing,
command names,
com,
colin watson,
colin,
client library,
client,
cid,
chsh,
christoph martin,
christoph anton mitterer,
chris evans,
chm,
check,
case conversion,
card,
caching web,
cabinet files,
ca certificates,
c library,
bz2 file,
business simulation game,
burchardt,
buffer sizes,
buffer overrun,
bt4,
browser technology,
broadcom,
boris zbarsky,
bob clary,
bitmap distribution format,
bind system,
bgp sessions,
bgp,
benjamin smedberg,
ben hawkes,
bcfg,
based bug tracking system,
bartlomiej balcerek,
authoritative server,
authentication procedure,
authentication module,
authentication,
assertion failure,
arbitrary web,
apache httpd,
apache authentication,
antonio martin,
ansgar burchardt,
andrew deason,
andres lopez,
andreas mayer,
alternate stylesheet,
aliz,
advisory number,
advanced configuration and power interface,
administrator privileges,
administrative policies,
adam zabrocki,
acpid,
Wireless
Skip to page:
1
2
3
...
5
-
-
19:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2479-1 - Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code.
-
19:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2479-1 - Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code.
-
19:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
19:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
19:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
17:18
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2477-1 - Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by unauthorized users.
-
17:18
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2477-1 - Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by unauthorized users.
-
17:18
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2477-1 - Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by unauthorized users.
-
-
7:08
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2475-1 - It was discovered that openssl did not correctly handle explicit Initialization Vectors for CBC encryption modes, as used in TLS 1.1, 1.2, and DTLS. An incorrect calculation would lead to an integer underflow and incorrect memory access, causing denial of service (application crash.)
-
7:08
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2475-1 - It was discovered that openssl did not correctly handle explicit Initialization Vectors for CBC encryption modes, as used in TLS 1.1, 1.2, and DTLS. An incorrect calculation would lead to an integer underflow and incorrect memory access, causing denial of service (application crash.)
-
7:08
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2475-1 - It was discovered that openssl did not correctly handle explicit Initialization Vectors for CBC encryption modes, as used in TLS 1.1, 1.2, and DTLS. An incorrect calculation would lead to an integer underflow and incorrect memory access, causing denial of service (application crash.)
-
-
12:20
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2474-1 - Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
-
12:20
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2474-1 - Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
-
-
16:53
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2473-1 - Tielei Wang discovered that OpenOffice.org does not allocate a large enough memory region when processing a specially crafted JPEG object, leading to a heap-based buffer overflow and potentially arbitrary code execution.
-
16:53
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2473-1 - Tielei Wang discovered that OpenOffice.org does not allocate a large enough memory region when processing a specially crafted JPEG object, leading to a heap-based buffer overflow and potentially arbitrary code execution.
-
16:53
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2473-1 - Tielei Wang discovered that OpenOffice.org does not allocate a large enough memory region when processing a specially crafted JPEG object, leading to a heap-based buffer overflow and potentially arbitrary code execution.
-
15:46
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2472-1 - Dave Love discovered that users who are allowed to submit jobs to a Grid Engine installation can escalate their privileges to root because the environment is not properly sanitized before creating processes.
-
15:46
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2472-1 - Dave Love discovered that users who are allowed to submit jobs to a Grid Engine installation can escalate their privileges to root because the environment is not properly sanitized before creating processes.
-
-
22:25
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
22:25
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
22:25
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
22:25
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2471-1 - Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.
-
22:25
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2471-1 - Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.
-
22:25
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2471-1 - Several vulnerabilities have been discovered in FFmpeg, a multimedia player, server and encoder. Multiple input validations in the decoders/ demuxers for Westwood Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3, DV, NSV, files could lead to the execution of arbitrary code.
-
-
14:47
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
14:47
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
14:47
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
8:50
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2469-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation.
-
-
21:02
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2468-1 - It was discovered that Apache POI, a Java implementation of the Microsoft Office file formats, would allocate arbitrary amounts of memory when processing crafted documents. This could impact the stability of the Java virtual machine.
-
21:02
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2468-1 - It was discovered that Apache POI, a Java implementation of the Microsoft Office file formats, would allocate arbitrary amounts of memory when processing crafted documents. This could impact the stability of the Java virtual machine.
-
21:02
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2468-1 - It was discovered that Apache POI, a Java implementation of the Microsoft Office file formats, would allocate arbitrary amounts of memory when processing crafted documents. This could impact the stability of the Java virtual machine.
-
21:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
21:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
21:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
21:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2466-1 - Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document.
-
21:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2466-1 - Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document.
-
21:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2466-1 - Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document.
-
20:59
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
20:59
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
20:59
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
-
17:18
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2464-2 - The latest security update, DSA-2464-1, for Icedove, Debian's version removal of UTF-7 support resulted in incorrect display of IMAP folder names.
-
-
18:30
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2459-2 - The recent quagga update, DSA-2459-1, introduced a memory leak in the bgpd process in some configurations.
-
18:30
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2459-2 - The recent quagga update, DSA-2459-1, introduced a memory leak in the bgpd process in some configurations.
-
-
15:28
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2464-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
15:28
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2464-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
15:28
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2464-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
15:26
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2462-2 - Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service. The initial update introduced a regression, which could lead to errors when processing some JPEG files.
-
15:26
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2462-2 - Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service. The initial update introduced a regression, which could lead to errors when processing some JPEG files.
-
15:26
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2462-2 - Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service. The initial update introduced a regression, which could lead to errors when processing some JPEG files.
-
-
8:56
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2463-1 - Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the "take ownership" privilege.
-
8:56
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2463-1 - Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the "take ownership" privilege.
-
-
9:24
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2462-1 - Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service.
-
9:24
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2462-1 - Several integer overflows and missing input validations were discovered in the ImageMagick image manipulation suite, resulting in the execution of arbitrary code or denial of service.
-
-
14:55
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2459-1 - Several vulnerabilities have been discovered in Quagga, a routing daemon.
-
-
11:33
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2454-2 - Tomas Hoger, Red Hat, discovered that the fix for CVE-2012-2110 for the 0.9.8 series of OpenSSL was incomplete. It has been assigned the CVE-2012-2131 identifier.
-
11:33
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2454-2 - Tomas Hoger, Red Hat, discovered that the fix for CVE-2012-2110 for the 0.9.8 series of OpenSSL was incomplete. It has been assigned the CVE-2012-2131 identifier.
-
11:33
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2454-2 - Tomas Hoger, Red Hat, discovered that the fix for CVE-2012-2110 for the 0.9.8 series of OpenSSL was incomplete. It has been assigned the CVE-2012-2131 identifier.
-
-
21:11
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2458-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
21:11
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2458-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
19:07
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2456-1 - Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.
-
19:07
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2456-1 - Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.
-
-
12:53
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2455-1 - Helmut Hummel of the typo3 security team discovered that typo3, a web content management system, is not properly sanitizing output of the exception handler. This allows an attacker to conduct cross-site scripting attacks if either third-party extensions are installed that do not sanitize this output on their own or in the presence of extensions using the extbase MVC framework which accept objects to controller actions.
-
12:53
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2455-1 - Helmut Hummel of the typo3 security team discovered that typo3, a web content management system, is not properly sanitizing output of the exception handler. This allows an attacker to conduct cross-site scripting attacks if either third-party extensions are installed that do not sanitize this output on their own or in the presence of extensions using the extbase MVC framework which accept objects to controller actions.
-
12:53
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2455-1 - Helmut Hummel of the typo3 security team discovered that typo3, a web content management system, is not properly sanitizing output of the exception handler. This allows an attacker to conduct cross-site scripting attacks if either third-party extensions are installed that do not sanitize this output on their own or in the presence of extensions using the extbase MVC framework which accept objects to controller actions.
-
12:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2454-1 - Multiple vulnerabilities have been found in OpenSSL. Ivan Nestlerode discovered a weakness in the CMS and PKCS #7 implementations that could allow an attacker to decrypt data via a Million Message Attack (MMA). It was discovered that a NULL pointer could be dereferenced when parsing certain S/MIME messages, leading to denial of service. Tavis Ormandy, Google Security Team, discovered a vulnerability in the way DER-encoded ASN.1 data is parsed that can result in a heap overflow.
-
12:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2454-1 - Multiple vulnerabilities have been found in OpenSSL. Ivan Nestlerode discovered a weakness in the CMS and PKCS #7 implementations that could allow an attacker to decrypt data via a Million Message Attack (MMA). It was discovered that a NULL pointer could be dereferenced when parsing certain S/MIME messages, leading to denial of service. Tavis Ormandy, Google Security Team, discovered a vulnerability in the way DER-encoded ASN.1 data is parsed that can result in a heap overflow.
-
-
18:16
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2453-2 - It was discovered that the last security update for gajim, DSA-2453-1, introduced a regression in certain environments.
-
18:16
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2453-2 - It was discovered that the last security update for gajim, DSA-2453-1, introduced a regression in certain environments.
-
8:23
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
8:23
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
8:23
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
-
12:37
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2451-1 - Several vulnerabilities have been discovered in puppet, a centralized configuration management system.
-
12:37
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2451-1 - Several vulnerabilities have been discovered in puppet, a centralized configuration management system.
-
-
16:12
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2450-1 - It was discovered that Samba, the SMB/CIFS file, print, and login server, contained a flaw in the remote procedure call (RPC) code which allowed remote code execution as the super user from an unauthenticated connection.
-
16:12
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2450-1 - It was discovered that Samba, the SMB/CIFS file, print, and login server, contained a flaw in the remote procedure call (RPC) code which allowed remote code execution as the super user from an unauthenticated connection.
-
16:12
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2450-1 - It was discovered that Samba, the SMB/CIFS file, print, and login server, contained a flaw in the remote procedure call (RPC) code which allowed remote code execution as the super user from an unauthenticated connection.
-
8:37
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2449-1 - It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against applications using sqlalchemy that do not implement their own filtering.
-
-
7:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2448-1 - It was discovered that a heap-based buffer overflow in InspIRCd could allow remote attackers to execute arbitrary code via a crafted DNS query.
-
7:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2448-1 - It was discovered that a heap-based buffer overflow in InspIRCd could allow remote attackers to execute arbitrary code via a crafted DNS query.
-
7:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2448-1 - It was discovered that a heap-based buffer overflow in InspIRCd could allow remote attackers to execute arbitrary code via a crafted DNS query.
-
-
17:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2446-1 - It was discovered that incorrect memory handling in the png_set_text2() function of the PNG library could lead to the execution of arbitrary code.
-
-
10:52
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2398-2 - cURL is a command-line tool and library for transferring data with URL syntax. It was discovered that the countermeasures against the Dai/Rogaway chosen-plaintext attack on SSL/TLS (CVE-2011-3389, "BEAST") cause interoperability issues with some server implementations. This update ads the the CURLOPT_SSL_OPTIONS and CURLSSLOPT_ALLOW_BEAST options to the library, and the - --ssl-allow-beast option to the "curl" program.
-
10:52
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2398-2 - cURL is a command-line tool and library for transferring data with URL syntax. It was discovered that the countermeasures against the Dai/Rogaway chosen-plaintext attack on SSL/TLS (CVE-2011-3389, "BEAST") cause interoperability issues with some server implementations. This update ads the the CURLOPT_SSL_OPTIONS and CURLSSLOPT_ALLOW_BEAST options to the library, and the - --ssl-allow-beast option to the "curl" program.
-
10:52
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2398-2 - cURL is a command-line tool and library for transferring data with URL syntax. It was discovered that the countermeasures against the Dai/Rogaway chosen-plaintext attack on SSL/TLS (CVE-2011-3389, "BEAST") cause interoperability issues with some server implementations. This update ads the the CURLOPT_SSL_OPTIONS and CURLSSLOPT_ALLOW_BEAST options to the library, and the - --ssl-allow-beast option to the "curl" program.
-
10:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2442-2 - The openarena update DSA-2442-1 introduced a regression in which servers would cease to respond to status requests after an uptime of several weeks.
-
10:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2445-1 - Several remote vulnerabilities have been discovered in the TYPO3 web content management framework.
-
-
16:50
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
16:50
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
16:50
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
-
19:04
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2443-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation.
-
19:04
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2443-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation.
-
19:04
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2443-1 - Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation.
-
-
13:36
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2442-1 - It has been discovered that spoofed "getstatus" UDP requests are being sent by attackers to servers for use with games derived from the Quake 3 engine (such as openarena). These servers respond with a packet flood to the victim whose IP address was impersonated by the attackers, causing a denial of service.
-
13:36
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2442-1 - It has been discovered that spoofed "getstatus" UDP requests are being sent by attackers to servers for use with games derived from the Quake 3 engine (such as openarena). These servers respond with a packet flood to the victim whose IP address was impersonated by the attackers, causing a denial of service.
-
-
17:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
17:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
17:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
17:21
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2440-1 - Matthew Hall discovered that many callers of the asn1_get_length_der function did not check the result against the overall buffer length before processing it further. This could result in out-of-bounds memory accesses and application crashes. Applications using GNUTLS are exposed to this issue.
-
17:21
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2440-1 - Matthew Hall discovered that many callers of the asn1_get_length_der function did not check the result against the overall buffer length before processing it further. This could result in out-of-bounds memory accesses and application crashes. Applications using GNUTLS are exposed to this issue.
-
17:21
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2440-1 - Matthew Hall discovered that many callers of the asn1_get_length_der function did not check the result against the overall buffer length before processing it further. This could result in out-of-bounds memory accesses and application crashes. Applications using GNUTLS are exposed to this issue.
-
-
20:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2439-1 - Glenn-Randers Pehrson discovered an buffer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
20:17
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2439-1 - Glenn-Randers Pehrson discovered an buffer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
20:17
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2439-1 - Glenn-Randers Pehrson discovered an buffer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
20:16
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2438-1 - It was discovered that Raptor, a RDF parser and serializer library, allows file inclusion through XML entities, resulting in information disclosure.
-
20:16
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2438-1 - It was discovered that Raptor, a RDF parser and serializer library, allows file inclusion through XML entities, resulting in information disclosure.
-
-
20:18
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2437-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
20:18
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2437-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
20:18
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2437-1 - Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client.
-
-
8:34
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
8:34
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
8:34
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
-
15:21
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2436-1 - It was discovered that the Apache FCGID module, a FastCGI implementation, did not properly enforce the FcgidMaxProcessesPerClass resource limit, rendering this control ineffective and potentially allowing a virtual host to consume excessive resources.
-
15:21
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2436-1 - It was discovered that the Apache FCGID module, a FastCGI implementation, did not properly enforce the FcgidMaxProcessesPerClass resource limit, rendering this control ineffective and potentially allowing a virtual host to consume excessive resources.
-
15:21
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2436-1 - It was discovered that the Apache FCGID module, a FastCGI implementation, did not properly enforce the FcgidMaxProcessesPerClass resource limit, rendering this control ineffective and potentially allowing a virtual host to consume excessive resources.
-
-
19:37
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2433-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:37
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2433-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:37
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2433-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
-
16:55
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2432-1 - Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library.
-
16:55
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2432-1 - Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library.
-
16:55
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2432-1 - Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library.
-
-
12:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2431-1 - Niko Tyni discovered two format string vulnerabilities in DBD::Pg, a Perl DBI driver for the PostgreSQL database server, which can be exploited by a rogue database server.
-
12:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2431-1 - Niko Tyni discovered two format string vulnerabilities in DBD::Pg, a Perl DBI driver for the PostgreSQL database server, which can be exploited by a rogue database server.
-
12:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2431-1 - Niko Tyni discovered two format string vulnerabilities in DBD::Pg, a Perl DBI driver for the PostgreSQL database server, which can be exploited by a rogue database server.
-
5:12
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2430-1 - Markus Vervier discovered a double free in the Python interface to the PAM library, which could lead to denial of service.
-
5:12
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2430-1 - Markus Vervier discovered a double free in the Python interface to the PAM library, which could lead to denial of service.
-
5:12
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2430-1 - Markus Vervier discovered a double free in the Python interface to the PAM library, which could lead to denial of service.
-
-
19:46
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2428-1 - Mateusz Jurczyk from the Google Security Team discovered several vulnerabilities in Freetype's parsing of BDF, Type1 and TrueType fonts, which could result in the execution of arbitrary code if a malformed font file is processed.
-
19:46
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2428-1 - Mateusz Jurczyk from the Google Security Team discovered several vulnerabilities in Freetype's parsing of BDF, Type1 and TrueType fonts, which could result in the execution of arbitrary code if a malformed font file is processed.
-
19:46
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2428-1 - Mateusz Jurczyk from the Google Security Team discovered several vulnerabilities in Freetype's parsing of BDF, Type1 and TrueType fonts, which could result in the execution of arbitrary code if a malformed font file is processed.
-
-
15:13
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2429-1 - Several security vulnerabilities were discovered in MySQL, a database management system. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.61, which includes additional changes, such as performance improvements and corrections for data loss defects.
-
15:13
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2429-1 - Several security vulnerabilities were discovered in MySQL, a database management system. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.61, which includes additional changes, such as performance improvements and corrections for data loss defects.
-
15:13
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2429-1 - Several security vulnerabilities were discovered in MySQL, a database management system. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.61, which includes additional changes, such as performance improvements and corrections for data loss defects.
-
-
16:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
16:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
16:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
-
12:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2425-1 - It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code.
-
12:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2425-1 - It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code.
-
12:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2425-1 - It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code.
-
11:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2424-1 - It was discovered that the XML::Atom Perl module did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
-
11:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2424-1 - It was discovered that the XML::Atom Perl module did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
-
11:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2424-1 - It was discovered that the XML::Atom Perl module did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
-
-
18:29
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2421-1 - Several security issues have been fixed in Moodle, a course management system for online learning.
-
8:03
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2420-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform.
-
-
16:36
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2419-1 - Two vulnerabilities were discovered in Puppet, a centralized configuration management tool.
-
16:36
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2418-1 - Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database.
-
16:35
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
16:35
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
16:35
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
-
14:45
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2416-1 - It was discovered that Notmuch, an email indexer, did not sufficiently escape Emacs MML tags. When using the Emacs interface, a user could be tricked into replying to a maliciously formatted message which could lead to files from the local machine being attached to the outgoing message.
-
-
19:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2417-1 - It was discovered that the internal hashing routine of libxml2, a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the hashing algorithm, it is possible to craft input that creates a large amount of collisions. As a result it is possible to perform denial of service attacks against applications using libxml2 functionality because of the computational overhead.
-
19:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2417-1 - It was discovered that the internal hashing routine of libxml2, a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the hashing algorithm, it is possible to craft input that creates a large amount of collisions. As a result it is possible to perform denial of service attacks against applications using libxml2 functionality because of the computational overhead.
-
19:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2417-1 - It was discovered that the internal hashing routine of libxml2, a library providing an extensive API to handle XML data, is vulnerable to predictable hash collisions. Given an attacker with knowledge of the hashing algorithm, it is possible to craft input that creates a large amount of collisions. As a result it is possible to perform denial of service attacks against applications using libxml2 functionality because of the computational overhead.
-
-
20:43
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2415-1 - Several vulnerabilities that can lead to the execution of arbitrary code have been discovered in libmodplug, a library for mod music based on ModPlug.
-
20:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2414-1 - Nicola Fioravanti discovered that F*X, a web service for transferring very large files, is not properly sanitizing input parameters of the "fup" script. An attacker can use this flaw to conduct reflected cross-site scripting attacks via various script parameters.
-
7:35
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2413-1 - Two buffer overflows have been discovered in libarchive, a library providing a flexible interface for reading and writing archives in various formats. The possible buffer overflows while reading is9660 or tar streams allow remote attackers to execute arbitrary code depending on the application that makes use of this functionality.
-
7:35
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2413-1 - Two buffer overflows have been discovered in libarchive, a library providing a flexible interface for reading and writing archives in various formats. The possible buffer overflows while reading is9660 or tar streams allow remote attackers to execute arbitrary code depending on the application that makes use of this functionality.
-
7:35
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2413-1 - Two buffer overflows have been discovered in libarchive, a library providing a flexible interface for reading and writing archives in various formats. The possible buffer overflows while reading is9660 or tar streams allow remote attackers to execute arbitrary code depending on the application that makes use of this functionality.
-
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
-
14:46
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2410-1 - Jueri Aedla discovered an integer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
14:46
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2410-1 - Jueri Aedla discovered an integer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
14:46
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2410-1 - Jueri Aedla discovered an integer overflow in the libpng PNG library, which could lead to the execution of arbitrary code if a malformed image is processed.
-
14:43
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
14:43
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
14:43
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
-
23:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2407-1 - It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client.
-
23:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2407-1 - It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client.
-
23:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2407-1 - It was discovered that a malicious CVS server could cause a heap overflow in the CVS client, potentially allowing the server to execute arbitrary code on the client.
-
23:41
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
23:41
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
23:41
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
-
15:14
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2403-2 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
16:10
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2404-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of QEMU, which is used in the xen-qemu-dm-4.0 packages. This vulnerability might enable to malicious guest systems to crash the host system or escalate their privileges.
-
16:10
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2404-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of QEMU, which is used in the xen-qemu-dm-4.0 packages. This vulnerability might enable to malicious guest systems to crash the host system or escalate their privileges.
-
16:10
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2404-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of QEMU, which is used in the xen-qemu-dm-4.0 packages. This vulnerability might enable to malicious guest systems to crash the host system or escalate their privileges.
-
-
16:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2384-2 - It was discovered that the last security update for cacti, DSA-2384-1, introduced a regression in lenny.
-
16:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2384-2 - It was discovered that the last security update for cacti, DSA-2384-1, introduced a regression in lenny.
-
-
12:37
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
12:37
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
-
16:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2402-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
16:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2400-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
15:31
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2401-1 - Several vulnerabilities have been found in Tomcat, a servlet and JSP engine.
-
-
18:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
18:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
18:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
11:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2397-1 - It was discovered that a buffer overflow in the Unicode library ICU could lead to the execution of arbitrary code.
-
11:17
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2397-1 - It was discovered that a buffer overflow in the Unicode library ICU could lead to the execution of arbitrary code.
-
11:17
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2397-1 - It was discovered that a buffer overflow in the Unicode library ICU could lead to the execution of arbitrary code.
-
-
15:35
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2396-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of KVM, a solution for full virtualization on x86 hardware, which could result in denial of service or privilege escalation.
-
15:35
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2396-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of KVM, a solution for full virtualization on x86 hardware, which could result in denial of service or privilege escalation.
-
15:35
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2396-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of KVM, a solution for full virtualization on x86 hardware, which could result in denial of service or privilege escalation.
-
15:34
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2395-1 - Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code.
-
15:34
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2395-1 - Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code.
Skip to page:
1
2
3
...
5