資訊聯播

DSA-2011 dpkg - path traversal

最新 Debian 安全通告 - 2010, 三月 10 - 00:00

William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content.

DSA-2010 kvm - privilege escalation/denial of service

最新 Debian 安全通告 - 2010, 三月 10 - 00:00

Several local vulnerabilities have been discovered in kvm, a full virtualization system. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-2009 tdiary - insufficient input sanitising

最新 Debian 安全通告 - 2010, 三月 9 - 00:00

It was discovered that tdiary, a communication-friendly weblog system, is prone to a cross-site scripting vulnerability due to insufficient input sanitising in the TrackBack transmission plugin.

DSA-2008 typo3-src - several vulnerabilities

最新 Debian 安全通告 - 2010, 三月 8 - 00:00

Several remote vulnerabilities have been discovered in the TYPO3 web content management framework: Cross-site scripting vulnerabilities have been discovered in both the frontend and the backend. Also, user data could be leaked. More details can be found in the Typo3 security advisory.

DSA-2007 cups - format string vulnerability

最新 Debian 安全通告 - 2010, 三月 3 - 00:00

Ronald Volgers discovered that the lppasswd component of the cups suite, the Common UNIX Printing System, is vulnerable to format string attacks due to insecure use of the LOCALEDIR environment variable. An attacker can abuse this behaviour to execute arbitrary code via crafted localization files and triggering calls to _cupsLangprintf(). This works as the lppasswd binary happens to be installed with setuid 0 permissions.

DSA-2006 sudo - several vulnerabilities

最新 Debian 安全通告 - 2010, 三月 2 - 00:00

Several vulnerabilities have been discovered in sudo, a program designed to allow a sysadmin to give limited root privileges to users. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-2004 samba - several vulnerabilities

最新 Debian 安全通告 - 2010, 二月 28 - 00:00

Two local vulnerabilities have been discovered in samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-2005 linux-2.6.24 - privilege escalation/denial of service/sensitive memory leak

最新 Debian 安全通告 - 2010, 二月 27 - 00:00

NOTE: This kernel update marks the final planned kernel security update for the 2.6.24 kernel in the Debian release 'etch'. Although security support for 'etch' officially ended on Feburary 15th, 2010, this update was already in preparation before that date.

DSA-2003 linux-2.6 - privilege escalation/denial of service

最新 Debian 安全通告 - 2010, 二月 22 - 00:00

NOTE: This kernel update marks the final planned kernel security update for the 2.6.18 kernel in the Debian release 'etch'. Although security support for 'etch' officially ended on Feburary 15th, 2010, this update was already in preparation before that date. A final update that includes fixes for these issues in the 2.6.24 kernel is also in preparation and will be released shortly.

DSA-2002 polipo - denial of service

最新 Debian 安全通告 - 2010, 二月 19 - 00:00

Several denial of service vulnerabilities have been discovered in polipo, a small, caching web proxy. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-2001 php5 - multiple vulnerabilities

最新 Debian 安全通告 - 2010, 二月 19 - 00:00

Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-2000 ffmpeg-debian - several vulnerabilities

最新 Debian 安全通告 - 2010, 二月 18 - 00:00

Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder, which also provides a range of multimedia libraries used in applications like MPlayer:

DSA-1999 xulrunner - several vulnerabilities

最新 Debian 安全通告 - 2010, 二月 18 - 00:00

Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1998 kdelibs - buffer overflow

最新 Debian 安全通告 - 2010, 二月 17 - 00:00

Maksymilian Arciemowicz discovered a buffer overflow in the internal string routines of the KDE core libraries, which could lead to the execution of arbitrary code.

DSA-1997 mysql-dfsg-5.0 - several vulnerabilities

最新 Debian 安全通告 - 2010, 二月 14 - 00:00

Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1996 linux-2.6 - privilege escalation/denial of service/sensitive memory leak

最新 Debian 安全通告 - 2010, 二月 12 - 00:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, sensitive memory leak or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1995 openoffice.org - several vulnerabilities

最新 Debian 安全通告 - 2010, 二月 12 - 00:00

Several vulnerabilities have been discovered in the OpenOffice.org office suite. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1994 ajaxterm - weak session IDs

最新 Debian 安全通告 - 2010, 二月 11 - 00:00

It was discovered that ajaxterm, a web-based terminal, generates weak and predictable session IDs, which might be used to hijack a session or cause a denial of service attack on a system that uses ajaxterm.

DSA-1993 otrs2 - sql injection

最新 Debian 安全通告 - 2010, 二月 10 - 00:00

It was discovered that otrs2, the Open Ticket Request System, does not properly sanitise input data that is used on SQL queries, which might be used to inject arbitrary SQL to, for example, escalate privileges on a system that uses otrs2.

DSA-1963 unbound - cryptographic implementation error

最新 Debian 安全通告 - 2009, 十二月 23 - 00:00

It was discovered that Unbound, a DNS resolver, does not properly check cryptographic signatures on NSEC3 records. As a result, zones signed with the NSEC3 variant of DNSSEC lose their cryptographic protection. (An attacker would still have to carry out an ordinary cache poisoning attack to add bad data to the cache.)

RSS feed