Multiple vulnerabilities have been discovered in the Xen hypervisor. The
Common Vulnerabilities and Exposures project identifies the following
problems:
Category Archives: Debian
Debian Security Advisories
DSA-3728 firefox-esr – security update
A use-after-free vulnerability in the SVG Animation was discovered in
the Mozilla Firefox web browser, allowing a remote attacker to cause a
denial of service (application crash) or execute arbitrary code, if a
user is tricked into opening a specially crafted website.
DSA-3727 hdf5 – security update
Cisco Talos discovered that hdf5, a file format and library for
storing scientific data, contained several vulnerabilities that could
lead to arbitrary code execution when handling untrusted data.
DSA-3725 icu – security update
Several vulnerabilities were discovered in the International Components
for Unicode (ICU) library.
DSA-3726 imagemagick – security update
Several issues have been discovered in ImageMagick, a popular set of
programs and libraries for image manipulation. These issues include
several problems in memory handling that can result in a denial of
service attack or in execution of arbitrary code by an attacker with
control on the image input.
DSA-3724 gst-plugins-good0.10 – security update
Chris Evans discovered that the GStreamer 0.10 plugin used to decode
files in the FLIC format allowed execution of arbitrary code. Further
details can be found in his advisory at
https://scarybeastsecurity.blogspot.de/2016/11/0day-exploit-advancing-exploitation.html
DSA-3723 gst-plugins-good1.0 – security update
Chris Evans discovered that the GStreamer 1.0 plugin used to decode
files in the FLIC format allowed execution of arbitrary code. Further
details can be found in his advisory at
https://scarybeastsecurity.blogspot.de/2016/11/0day-exploit-advancing-exploitation.html
DSA-3722 vim – security update
Florian Larysch and Bram Moolenaar discovered that vim, an enhanced vi
editor, does not properly validate values for the filetype
,
syntax
and keymap
options, which may result in the execution of
arbitrary code if a file with a specially crafted modeline is opened.
DSA-3720 tomcat8 – security update
Multiple security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine, which may result in possible timing attacks to
determine valid user names, bypass of the SecurityManager, disclosure of
system properties, unrestricted access to global resources, arbitrary
file overwrites, and potentially escalation of privileges.
DSA-3719 wireshark – security update
It was discovered that wireshark, a network protocol analyzer,
contained several vulnerabilities in the dissectors for DCERPC,
AllJoyn, DTN, and OpenFlow, that could lead to various crashes,
denial-of-service, or execution of arbitrary code.