Multiple vulnerabilities have been discovered in the libtiff library
and the included tools tiff2rgba, rgb2ycbcr, tiffcp, tiffcrop, tiff2pdf
and tiffsplit, which may result in denial of service, memory disclosure
or the execution of arbitrary code.
Monthly Archives: January 2017
DSA-3764 pdns – security update
Multiple vulnerabilities have been discovered in pdns, an authoritative
DNS server. The Common Vulnerabilities and Exposures project identifies
the following problems:
DSA-3763 pdns-recursor – security update
Florian Heinz and Martin Kluge reported that pdns-recursor, a recursive
DNS server, parses all records present in a query regardless of whether
they are needed or even legitimate, allowing a remote, unauthenticated
attacker to cause an abnormal CPU usage load on the pdns server,
resulting in a partial denial of service if the system becomes
overloaded.
Vuln: GNU ed CVE-2017-5357 Denial of Service Vulnerability
GNU ed CVE-2017-5357 Denial of Service Vulnerability
Vuln: Zabbix CVE-2016-10134 SQL Injection Vulnerability
Zabbix CVE-2016-10134 SQL Injection Vulnerability
Vuln: ICU CVE-2016-6293 Out of Bounds Read Denial of Service Vulnerability
ICU CVE-2016-6293 Out of Bounds Read Denial of Service Vulnerability
GLSA 201701-35: Mozilla SeaMonkey: Multiple vulnerabilities
DSA-3761 rabbitmq-server – security update
It was discovered that RabbitMQ, an implementation of the AMQP
protocol, didn’t correctly validate MQTT (MQ Telemetry Transport)
connection authentication. This allowed anyone to login to an existing
user account without having to provide a password.
CVE-2016-9299
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVE-2016-10027
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the “starttls” feature from a server response.