Multiple vulnerabilities have been discovered in Asterisk, an open source
PBX and telephony toolkit, which may result in denial of service or
incorrect certificate validation.
Category Archives: Debian
Debian Security Advisories
DSA-3698 php5 – security update
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development.
DSA-3697 kdepimlibs – security update
Roland Tapken discovered that insufficient input sanitising in KMail’s
plain text viewer allowed the injection of HTML code.
DSA-3696 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
DSA-3694 tor – security update
It has been discovered that Tor treats the contents of some buffer
chunks as if they were a NUL-terminated string. This issue could
enable a remote attacker to crash a Tor client, hidden service, relay,
or authority.
DSA-3695 quagga – security update
It was discovered that the zebra daemon in the Quagga routing suite
suffered from a stack-based buffer overflow when processing IPv6
Neighbor Discovery messages.
DSA-3693 libgd2 – security update
Multiple vulnerabilities have been discovered in the GD Graphics Library,
which may result in denial of service or potentially the execution of
arbitrary code if a malformed file is processed.
DSA-3692 freeimage – security update
Multiple vulnerabilities were discovered in the FreeImage multimedia
library, which might result in denial of service or the execution of
arbitrary code if a malformed XMP or RAW image is processed.
DSA-3691 ghostscript – security update
Several vulnerabilities were discovered in Ghostscript, the GPL
PostScript/PDF interpreter, which may lead to the execution of arbitrary
code or information disclosure if a specially crafted Postscript file is
processed.
DSA-3690 icedove – security update
Multiple security issues have been found in Icedove, Debian’s version of
the Mozilla Thunderbird mail client: Multiple memory safety errors may
lead to the execution of arbitrary code or denial of service.