«
Expand/Collapse
678 items tagged "debian linux"
Related tags:
debian security [+],
internet suite [+],
web scripting language [+],
rendering services [+],
ogg vorbis [+],
max input [+],
lenny [+],
xen virtual machine [+],
vasiliy kulikov [+],
user [+],
transfer library [+],
tor [+],
stefan esser [+],
status requests [+],
stable distribution [+],
ssh daemon [+],
sql toolkit [+],
sql database [+],
server [+],
security checks [+],
ruby [+],
resume builder [+],
proftpd [+],
privacy tool [+],
postscript type [+],
popular library [+],
pidgin [+],
oracle java [+],
niels heinen [+],
mozilla thunderbird [+],
memory leak [+],
matthew hall [+],
matthew daley [+],
mail client [+],
library implementation [+],
ldap servers [+],
kulikov [+],
kerberos 5 [+],
javaserver faces [+],
javascript statements [+],
jabber client [+],
instrumentation system [+],
huzaifa sidhpurwala [+],
host list [+],
folder names [+],
ferdinand smit [+],
fastcgi applications [+],
example scripts [+],
electronic portfolio [+],
doc [+],
dns [+],
denial of service [+],
cves [+],
course management system [+],
command line parameters [+],
code execution [+],
cid [+],
cdf format [+],
buffer overflows [+],
buffer overflow [+],
based bug tracking system [+],
bartlomiej balcerek [+],
asterisk pbx [+],
apache httpd server [+],
administrator privileges [+],
dokuwiki [+],
dave love [+],
danny fullerton [+],
linux security [+],
security [+],
debian [+],
advisory [+],
png library [+],
jsp engine [+],
ziv,
zephyr,
yang dingning,
xml input,
x freetype,
willem pinckaers,
wikiwiki,
webmail application,
web frontend,
web application framework,
watson,
vlc,
vincent,
value,
user mode linux,
update,
unprivileged users,
undefined symbol,
txt,
tomas hoger,
tim zingelmann,
tiff library,
tiff,
terminal multiplexer,
template parameter,
system clock,
symlink attack,
stefan goebel,
src,
sql injection,
security vulnerabilities,
security advisory,
sebastian krahmer,
sanitizing,
sanitization,
runtime environment,
rra,
root user,
root privileges,
robert swiecki,
riku hietamaki,
ricardo narvaja,
request tracker,
regression,
query execution,
python,
postscript pdf,
postscript,
position error,
png files,
player server,
philip martin,
pdf,
pcscd,
paul belanger,
oprofile,
openssl libraries,
openoffice org office suite,
office productivity suite,
office,
network traffic analyzer,
network security services,
network protocol analyzer,
nahuel,
mysql database server,
mplayer,
moritz naumann,
minh,
metalink,
memory structures,
mediawiki,
md5 hashes,
matthew nicholson,
marc schoenefeld,
maildrop,
mail transfer agent,
login attack,
location,
linux,
kevin finisterre,
kde desktop environment,
joel voss,
jayachandran,
jamie strandboge,
irc commands,
irc,
interactive mapping applications,
input validation,
input,
image,
iceweasel,
hypertext preprocessor,
helin,
gnu c library,
gabble,
ftp daemon,
font library,
font,
filename,
file,
engine library,
ejabberd,
dylan simon,
dsa,
download,
dns root,
dns configurations,
debian version,
debian package,
data validation,
daniel danner,
dan rosenberg,
cyrus imap server,
cyrus imap,
csrf,
cronjob,
cookie value,
content management framework,
content disposition,
compression utilities,
command names,
com,
colin watson,
colin,
client,
christoph martin,
chris evans,
c. michael pilat,
c library,
bmp jpeg,
authentication procedure,
authentication,
attacker,
arbitrary code execution,
application crash,
apache httpd,
andres lopez,
access
-
-
19:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2479-1 - Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code.
-
19:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2479-1 - Jueri Aedla discovered an off-by-one in libxml2, which could result in the execution of arbitrary code.
-
19:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
19:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
19:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2478-1 - It was discovered that sudo misparsed network masks used in Host and Host_List stanzas. This allowed the execution of commands on hosts, where the user would not be allowed to run the specified command.
-
-
17:25
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2476-1 - intrigeri discovered a format string error in pidgin-otr, an off-the-record messaging plugin for Pidgin.
-
17:25
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2476-1 - intrigeri discovered a format string error in pidgin-otr, an off-the-record messaging plugin for Pidgin.
-
-
12:20
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2474-1 - Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
-
12:20
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2474-1 - Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
-
12:20
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2474-1 - Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
-
-
15:46
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2472-1 - Dave Love discovered that users who are allowed to submit jobs to a Grid Engine installation can escalate their privileges to root because the environment is not properly sanitized before creating processes.
-
15:46
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2472-1 - Dave Love discovered that users who are allowed to submit jobs to a Grid Engine installation can escalate their privileges to root because the environment is not properly sanitized before creating processes.
-
15:46
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2472-1 - Dave Love discovered that users who are allowed to submit jobs to a Grid Engine installation can escalate their privileges to root because the environment is not properly sanitized before creating processes.
-
-
22:25
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
22:25
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
22:25
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2457-2 - The updates DSA-2457 and DSA-2458 for Iceweasel and Icedove introduced a regression, which could lead to crashes when interpreting some Javascript statements.
-
-
14:47
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
14:47
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
14:47
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2670-1 - Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from release announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches.
-
-
21:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2422-2 - A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression.
-
21:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
21:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
21:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2467-1 - It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.
-
20:59
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
20:59
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
20:59
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2465-1 - De Eindbazen discovered that PHP, when run with mod_cgi, will interpret a query string as command line parameters, allowing to execute arbitrary code.
-
-
17:18
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2464-2 - The latest security update, DSA-2464-1, for Icedove, Debian's version removal of UTF-7 support resulted in incorrect display of IMAP folder names.
-
17:18
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2464-2 - The latest security update, DSA-2464-1, for Icedove, Debian's version removal of UTF-7 support resulted in incorrect display of IMAP folder names.
-
17:18
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2464-2 - The latest security update, DSA-2464-1, for Icedove, Debian's version removal of UTF-7 support resulted in incorrect display of IMAP folder names.
-
-
18:30
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2459-2 - The recent quagga update, DSA-2459-1, introduced a memory leak in the bgpd process in some configurations.
-
18:30
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2459-2 - The recent quagga update, DSA-2459-1, introduced a memory leak in the bgpd process in some configurations.
-
18:30
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2459-2 - The recent quagga update, DSA-2459-1, introduced a memory leak in the bgpd process in some configurations.
-
-
8:56
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2463-1 - Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the "take ownership" privilege.
-
8:56
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2463-1 - Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the "take ownership" privilege.
-
8:56
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2463-1 - Ivano Cristofolini discovered that insufficient security checks in Samba's handling of LSA RPC calls could lead to privilege escalation by gaining the "take ownership" privilege.
-
-
21:11
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2458-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
21:11
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2458-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
19:07
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2457-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
19:07
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2456-1 - Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.
-
19:07
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2456-1 - Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.
-
19:07
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2456-1 - Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.
-
-
18:16
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2453-2 - It was discovered that the last security update for gajim, DSA-2453-1, introduced a regression in certain environments.
-
18:16
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2453-2 - It was discovered that the last security update for gajim, DSA-2453-1, introduced a regression in certain environments.
-
18:16
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2453-2 - It was discovered that the last security update for gajim, DSA-2453-1, introduced a regression in certain environments.
-
8:23
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
8:23
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
8:23
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2452-1 - Niels Heinen noticed a security issue with the default Apache configuration on Debian if certain scripting modules like mod_php or mod_rivet are installed. The problem arises because the directory /usr/share/doc, which is mapped to the URL /doc, may contain example scripts that can be executed by requests to this URL. Although access to the URL /doc is restricted to connections from localhost, this still creates security issues in two specific configurations.
-
-
8:37
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2449-1 - It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against applications using sqlalchemy that do not implement their own filtering.
-
8:37
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2449-1 - It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against applications using sqlalchemy that do not implement their own filtering.
-
8:37
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2449-1 - It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against applications using sqlalchemy that do not implement their own filtering.
-
-
17:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2446-1 - It was discovered that incorrect memory handling in the png_set_text2() function of the PNG library could lead to the execution of arbitrary code.
-
-
10:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2442-2 - The openarena update DSA-2442-1 introduced a regression in which servers would cease to respond to status requests after an uptime of several weeks.
-
10:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2442-2 - The openarena update DSA-2442-1 introduced a regression in which servers would cease to respond to status requests after an uptime of several weeks.
-
10:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2442-2 - The openarena update DSA-2442-1 introduced a regression in which servers would cease to respond to status requests after an uptime of several weeks.
-
-
16:50
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
16:50
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
16:50
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2444-1 - It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field.
-
-
17:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
17:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
17:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2441-1 - Matthew Hall discovered that GNUTLS does not properly handle truncated GenericBlockCipher structures nested inside TLS records, leading to crashes in applications using the GNUTLS library.
-
-
8:34
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
8:34
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
8:34
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2434-1 - Matthew Daley discovered a memory disclosure vulnerability in nginx. In previous versions of this web server, an attacker can receive the content of previously freed memory if an upstream server returned a specially crafted HTTP response, potentially exposing sensitive information.
-
-
16:01
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
16:01
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
16:01
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2427-1 - Two security vulnerabilities related to EXIF processing were discovered in ImageMagick, a suite of programs to manipulate images.
-
-
18:29
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2422-1 - The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes.
-
18:29
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2421-1 - Several security issues have been fixed in Moodle, a course management system for online learning.
-
8:03
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2420-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform.
-
8:03
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2420-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform.
-
-
16:36
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2418-1 - Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database.
-
16:35
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
16:35
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
16:35
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2414-2 - It was discovered that the last security update for F*X, DSA-2414-1, introduced a regression. Updated packages are now available to address this problem.
-
-
20:43
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2415-1 - Several vulnerabilities that can lead to the execution of arbitrary code have been discovered in libmodplug, a library for mod music based on ModPlug.
-
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2411-1 - It was discovered that mumble, a VoIP client, does not probably manage permission on its user-specific configuration files, allowing other local users on the system to access them.
-
18:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
18:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2412-1 - It was discovered that a heap overflow in the Vorbis audio compression library could lead to the execution of arbitrary code if a malformed Ogg Vorbis file is processed.
-
-
14:43
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
14:43
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
14:43
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2409-1 - Several vulnerabilities have been discovered in debdiff, a script used to compare two Debian packages, which is part of the devscripts package.
-
-
23:41
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
23:41
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
23:41
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2406-1 - Several vulnerabilities have been discovered in Icedove, Debian's variant of the Mozilla Thunderbird code base.
-
-
15:14
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2403-2 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
15:14
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2403-2 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
15:14
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2403-2 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
-
16:42
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2384-2 - It was discovered that the last security update for cacti, DSA-2384-1, introduced a regression in lenny.
-
16:42
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2384-2 - It was discovered that the last security update for cacti, DSA-2384-1, introduced a regression in lenny.
-
-
12:37
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
12:37
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
12:37
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2403-1 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
-
-
16:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2402-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
15:31
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2401-1 - Several vulnerabilities have been found in Tomcat, a servlet and JSP engine.
-
-
18:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
18:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
18:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2399-2 - A regression was found in the fix for PHP's XSLT transformations. Updated packages are now available to address this regression.
-
-
20:19
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2301-2 - It was discovered that the last security update for Ruby on Rails, DSA-2301-1, introduced a regression in the libactionpack-ruby package.
-
20:19
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2301-2 - It was discovered that the last security update for Ruby on Rails, DSA-2301-1, introduced a regression in the libactionpack-ruby package.
-
20:19
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2301-2 - It was discovered that the last security update for Ruby on Rails, DSA-2301-1, introduced a regression in the libactionpack-ruby package.
-
8:17
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2391-1 - Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web.
-
-
18:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2388-1 - Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.
-
18:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2388-1 - Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.
-
18:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2388-1 - Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.
-
-
19:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2387-1 - timtai1 discovered that simpleSAMLphp, an authentication and federation platform, is vulnerable to a cross site scripting attack, allowing a remote attacker to access sensitive client data.
-
19:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2387-1 - timtai1 discovered that simpleSAMLphp, an authentication and federation platform, is vulnerable to a cross site scripting attack, allowing a remote attacker to access sensitive client data.
-
19:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2387-1 - timtai1 discovered that simpleSAMLphp, an authentication and federation platform, is vulnerable to a cross site scripting attack, allowing a remote attacker to access sensitive client data.
-
-
13:26
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2379-1 - It was discovered that the Key Distribution Center (KDC) in Kerberos 5 crashes when processing certain crafted requests.
-
13:26
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2379-1 - It was discovered that the Key Distribution Center (KDC) in Kerberos 5 crashes when processing certain crafted requests.
-
13:26
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2379-1 - It was discovered that the Key Distribution Center (KDC) in Kerberos 5 crashes when processing certain crafted requests.
-
-
9:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2263-2 - Advisory DSA 2363-1 did not include a package for the Debian 5.0 'Lenny' suite at that time. This update adds that package.
-
9:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2263-2 - Advisory DSA 2363-1 did not include a package for the Debian 5.0 'Lenny' suite at that time. This update adds that package.
-
9:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2263-2 - Advisory DSA 2363-1 did not include a package for the Debian 5.0 'Lenny' suite at that time. This update adds that package.
-
-
14:22
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2369-1 - It was discovered that libsoup2.4, a HTTP library implementation in C, is not properly validating input when processing requests made to SoupServer. A remote attacker can exploit this flaw to access system files via a directory traversal attack.
-
14:22
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2369-1 - It was discovered that libsoup2.4, a HTTP library implementation in C, is not properly validating input when processing requests made to SoupServer. A remote attacker can exploit this flaw to access system files via a directory traversal attack.
-
14:22
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2369-1 - It was discovered that libsoup2.4, a HTTP library implementation in C, is not properly validating input when processing requests made to SoupServer. A remote attacker can exploit this flaw to access system files via a directory traversal attack.
-
11:44
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2370-1 - It was discovered that Unbound, a recursive DNS resolver, would crash when processing certain malformed DNS responses from authoritative DNS servers, leading to denial of service.
-
11:44
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2370-1 - It was discovered that Unbound, a recursive DNS resolver, would crash when processing certain malformed DNS responses from authoritative DNS servers, leading to denial of service.
-
11:44
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2370-1 - It was discovered that Unbound, a recursive DNS resolver, would crash when processing certain malformed DNS responses from authoritative DNS servers, leading to denial of service.
-
-
15:10
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2367-1 - Several vulnerabilities have been discovered in Asterisk, an Open Source PBX and telephony toolkit.
-
-
13:41
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2364-1 - The Debian X wrapper enforces that the X server can only be started from a console. "vladz" discovered that this wrapper could be bypassed.
-
13:41
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2364-1 - The Debian X wrapper enforces that the X server can only be started from a console. "vladz" discovered that this wrapper could be bypassed.
-
13:41
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2364-1 - The Debian X wrapper enforces that the X server can only be started from a console. "vladz" discovered that this wrapper could be bypassed.
-
-
15:58
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2359-1 - It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParameters is set to true.
-
15:58
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2359-1 - It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParameters is set to true.
-
15:58
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2359-1 - It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParameters is set to true.
-
-
6:44
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2358-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Java platform. This combines the two previous openjdk-6 advisories, DSA-2311-1 and DSA-2356-1.
-
6:44
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2358-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Java platform. This combines the two previous openjdk-6 advisories, DSA-2311-1 and DSA-2356-1.
-
6:44
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2358-1 - Several vulnerabilities have been discovered in OpenJDK, an implementation of the Java platform. This combines the two previous openjdk-6 advisories, DSA-2311-1 and DSA-2356-1.
-
-
17:14
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2351-1 - Huzaifa Sidhpurwala discovered a buffer overflow in Wireshark's ERF dissector, which could lead to the execution of arbitrary code.
-
17:14
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2351-1 - Huzaifa Sidhpurwala discovered a buffer overflow in Wireshark's ERF dissector, which could lead to the execution of arbitrary code.
-
17:14
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2351-1 - Huzaifa Sidhpurwala discovered a buffer overflow in Wireshark's ERF dissector, which could lead to the execution of arbitrary code.
-
17:26
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2350-1 - It was discovered that missing input sanitizing in Freetype's processing of CID-keyed fonts could lead to the execution of arbitrary code.
-
17:26
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2350-1 - It was discovered that missing input sanitizing in Freetype's processing of CID-keyed fonts could lead to the execution of arbitrary code.
-
17:26
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2350-1 - It was discovered that missing input sanitizing in Freetype's processing of CID-keyed fonts could lead to the execution of arbitrary code.
-
-
11:11
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2349-1 - Two vulnerabilities have been found in SPIP, a website engine for publishing, which allow privilege escalation to site administrator privileges and cross-site scripting.
-
11:11
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2349-1 - Two vulnerabilities have been found in SPIP, a website engine for publishing, which allow privilege escalation to site administrator privileges and cross-site scripting.
-
11:11
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2349-1 - Two vulnerabilities have been found in SPIP, a website engine for publishing, which allow privilege escalation to site administrator privileges and cross-site scripting.
-
-
18:27
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2346-2 - The ProFTPD security update, DSA-2346-1, introduced a regression, preventing successful TLS connections. This regression does not affected the stable distribution (squeeze), nor the testing and unstable distributions.
-
18:27
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2346-2 - The ProFTPD security update, DSA-2346-1, introduced a regression, preventing successful TLS connections. This regression does not affected the stable distribution (squeeze), nor the testing and unstable distributions.
-
18:27
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2346-2 - The ProFTPD security update, DSA-2346-1, introduced a regression, preventing successful TLS connections. This regression does not affected the stable distribution (squeeze), nor the testing and unstable distributions.
-
-
20:40
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2346-1 - Several vulnerabilities were discovered in ProFTPD, an FTP server. ProFTPD incorrectly uses data from an unencrypted input buffer after encryption has been enabled with STARTTLS, an issue similar to CVE-2011-0411. ProFTPD uses a response pool after freeing it under exceptional conditions, possibly leading to remote code execution.
-
20:40
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2346-1 - Several vulnerabilities were discovered in ProFTPD, an FTP server. ProFTPD incorrectly uses data from an unencrypted input buffer after encryption has been enabled with STARTTLS, an issue similar to CVE-2011-0411. ProFTPD uses a response pool after freeing it under exceptional conditions, possibly leading to remote code execution.
-
20:40
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2346-1 - Several vulnerabilities were discovered in ProFTPD, an FTP server. ProFTPD incorrectly uses data from an unencrypted input buffer after encryption has been enabled with STARTTLS, an issue similar to CVE-2011-0411. ProFTPD uses a response pool after freeing it under exceptional conditions, possibly leading to remote code execution.
-
-
10:36
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2342-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
10:36
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2342-1 - Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey.
-
10:21
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2341-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
10:21
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2341-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
10:21
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2341-1 - Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian.
-
-
7:04
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2340-1 - magnum discovered that the blowfish password hashing used amongst others in PostgreSQL contained a weakness that would give passwords with 8 bit characters the same hash as weaker equivalents.
-
7:04
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2340-1 - magnum discovered that the blowfish password hashing used amongst others in PostgreSQL contained a weakness that would give passwords with 8 bit characters the same hash as weaker equivalents.
-
7:04
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2340-1 - magnum discovered that the blowfish password hashing used amongst others in PostgreSQL contained a weakness that would give passwords with 8 bit characters the same hash as weaker equivalents.
-
-
14:13
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2334-1 - Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder.
-
14:13
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2334-1 - Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder.
-
-
15:09
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2333-1 - Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers.
-
15:09
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2333-1 - Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers.
-
15:09
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2333-1 - Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers.
-
-
14:47
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2323-1 - Multiple security issues were discovered by Vasiliy Kulikov in radvd, an IPv6 Router Advertisement daemon.
-
14:47
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2323-1 - Multiple security issues were discovered by Vasiliy Kulikov in radvd, an IPv6 Router Advertisement daemon.
-
14:47
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2323-1 - Multiple security issues were discovered by Vasiliy Kulikov in radvd, an IPv6 Router Advertisement daemon.
-
14:21
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2331-1 - It has been discovered by "frosty_un" that a design flaw in Tor, an online privacy tool, allows malicious relay servers to learn certain information that they should not be able to learn. Specifically, a relay that a user connects to directly could learn which other relays that user is connected to directly. In combination with other attacks, this issue can lead to deanonymizing the user.
-
14:21
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2331-1 - It has been discovered by "frosty_un" that a design flaw in Tor, an online privacy tool, allows malicious relay servers to learn certain information that they should not be able to learn. Specifically, a relay that a user connects to directly could learn which other relays that user is connected to directly. In combination with other attacks, this issue can lead to deanonymizing the user.
-
14:21
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2331-1 - It has been discovered by "frosty_un" that a design flaw in Tor, an online privacy tool, allows malicious relay servers to learn certain information that they should not be able to learn. Specifically, a relay that a user connects to directly could learn which other relays that user is connected to directly. In combination with other attacks, this issue can lead to deanonymizing the user.
-
-
7:51
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2329-1 - Bartlomiej Balcerek discovered several buffer overflows in torque server, a PBS-derived batch processing server. This allows an attacker to crash the service or execute arbitrary code with privileges of the server via crafted job or host names.
-
7:51
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2329-1 - Bartlomiej Balcerek discovered several buffer overflows in torque server, a PBS-derived batch processing server. This allows an attacker to crash the service or execute arbitrary code with privileges of the server via crafted job or host names.
-
7:51
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2329-1 - Bartlomiej Balcerek discovered several buffer overflows in torque server, a PBS-derived batch processing server. This allows an attacker to crash the service or execute arbitrary code with privileges of the server via crafted job or host names.
-
-
7:45
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2327-1 - Ferdinand Smit discovered that libfcgi-perl, a Perl module for writing FastCGI applications, is incorrectly restoring environment variables of a prior request in subsequent requests. In some cases this may lead to authentication bypasses or worse.
-
7:45
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2327-1 - Ferdinand Smit discovered that libfcgi-perl, a Perl module for writing FastCGI applications, is incorrectly restoring environment variables of a prior request in subsequent requests. In some cases this may lead to authentication bypasses or worse.
-
7:45
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2327-1 - Ferdinand Smit discovered that libfcgi-perl, a Perl module for writing FastCGI applications, is incorrectly restoring environment variables of a prior request in subsequent requests. In some cases this may lead to authentication bypasses or worse.
-
15:39
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2321-1 - A cross-site scriping vulnerability was discovered in the rst parser of Moin, a Python clone of WikiWiki.
-
15:39
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2321-1 - A cross-site scriping vulnerability was discovered in the rst parser of Moin, a Python clone of WikiWiki.
-
15:39
»
Packet Storm Security Misc. Files
Debian Linux Security Advisory 2321-1 - A cross-site scriping vulnerability was discovered in the rst parser of Moin, a Python clone of WikiWiki.
-
-
9:41
»
Packet Storm Security Advisories
Debian Linux Security Advisory 2320-1 - The dokuwiki update included in Debian Lenny 5.0.9 to address a cross site scripting issue (CVE-2011-2510) had a regression rendering links to external websites broken. This update corrects that regression.
-
9:41
»
Packet Storm Security Recent Files
Debian Linux Security Advisory 2320-1 - The dokuwiki update included in Debian Lenny 5.0.9 to address a cross site scripting issue (CVE-2011-2510) had a regression rendering links to external websites broken. This update corrects that regression.