Sécurité Debian

DSA-1666 libxml2 - several vulnerabilities

Sécurité Debian - lun, 2008-11-17 01:00

Several vulnerabilities have been discovered in the GNOME XML library. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1665 libcdaudio - heap overflow

Sécurité Debian - mer, 2008-11-12 01:00

It was discovered that a heap overflow in the CDDB retrieval code of libcdaudio, a library for controlling a CD-ROM when playing audio CDs, may result in the execution of arbitrary code.

Catégories: Sécurité Debian

DSA-1664 ekg - missing input sanitising

Sécurité Debian - lun, 2008-11-10 01:00

It was discovered that ekg, a console Gadu Gadu client performs insufficient input sanitising in the code to parse contact descriptions, which may result in denial of service.

Catégories: Sécurité Debian

DSA-1663 net-snmp - several vulnerabilities

Sécurité Debian - dim, 2008-11-09 01:00

Several vulnerabilities have been discovered in NET SNMP, a suite of Simple Network Management Protocol applications. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1663 net-snmp - several vulnerabilities

Sécurité Debian - dim, 2008-11-09 01:00

Several vulnerabilities have been discovered in NET SNMP, a suite of Simple Network Management Protocol applications. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1662 mysql-dfsg-5.0 - authorization bypass

Sécurité Debian - jeu, 2008-11-06 01:00

A symlink traversal vulnerability was discovered in MySQL, a relational database server. The weakness could permit an attacker having both CREATE TABLE access to a database and the ability to execute shell commands on the database server to bypass MySQL access controls, enabling them to write to ...

Catégories: Sécurité Debian

DSA-1661 openoffice.org - several vulnerabilities

Sécurité Debian - mer, 2008-10-29 01:00

Several vulnerabilities have been discovered in the OpenOffice.org office suite:

Catégories: Sécurité Debian

DSA-1660 clamav - null pointer dereference, resource exhaustation

Sécurité Debian - dim, 2008-10-26 00:00

Several denial-of-service vulnerabilities have been discovered in the ClamAV anti-virus toolkit:

Catégories: Sécurité Debian

DSA-1659 libspf2 - buffer overflow

Sécurité Debian - jeu, 2008-10-23 00:00

Dan Kaminsky discovered that libspf2, an implementation of the Sender Policy Framework (SPF) used by mail servers for mail filtering, handles malformed TXT records incorrectly, leading to a buffer overflow condition (CVE-2008-2...

DSA-1658 dbus - programming error

Sécurité Debian - mer, 2008-10-22 00:00

Colin Walters discovered that the dbus_signature_validate function in dbus, a simple interprocess messaging system, is prone to a denial of service attack.

Catégories: Sécurité Debian

DSA-1657 qemu - insecure temporary files

Sécurité Debian - lun, 2008-10-20 00:00

Dmitry E. Oboukhov discovered that the qemu-make-debian-root script in qemu, fast processor emulator, creates temporary files insecurely, which may lead to a local denial of service through symlink attacks.

Catégories: Sécurité Debian

DSA-1656 cupsys - several vulnerabilities

Sécurité Debian - lun, 2008-10-20 00:00

Several local vulnerabilities have been discovered in the Common UNIX Printing System. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1655 linux-2.6.24 - denial of service/information leak/privilege escalation

Sécurité Debian - jeu, 2008-10-16 00:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, privilege escalation or a leak of sensitive data. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1654 libxml2 - buffer overflow

Sécurité Debian - mar, 2008-10-14 00:00

It was discovered that libxml2, the GNOME XML library, didn't correctly handle long entity names. This could allow the execution of arbitrary code via a malicious XML file.

Catégories: Sécurité Debian

DSA-1653 linux-2.6 - denial of service/privilege escalation

Sécurité Debian - lun, 2008-10-13 00:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1652 ruby1.9 - several vulnerabilities

Sécurité Debian - dim, 2008-10-12 00:00

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service and other security problems. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1651 ruby1.8 - several vulnerabilities

Sécurité Debian - dim, 2008-10-12 00:00

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service and other security problems. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1650 openldap2.3 - denial of service

Sécurité Debian - dim, 2008-10-12 00:00

Cameron Hotchkies discovered that the OpenLDAP server slapd, a free implementation of the Lightweight Directory Access Protocol, could be crashed by sending malformed ASN1 requests.

Catégories: Sécurité Debian

DSA-1649 iceweasel - several vulnerabilities

Sécurité Debian - mer, 2008-10-08 00:00

Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems:

Catégories: Sécurité Debian

DSA-1648 mon - insecure temporary files

Sécurité Debian - mer, 2008-10-08 00:00

Dmitry E. Oboukhov discovered that the test.alert script used in one of the alert functions in mon, a system to monitor hosts or services and alert about problems, creates temporary files insecurely, which may lead to a local denial of service through symlink attacks.

Catégories: Sécurité Debian