Several vulnerabilities were discovered in wordpress, a web blogging
tool, which could allow remote attackers to compromise a site via
cross-site scripting, bypass restrictions, obtain sensitive
revision-history information, or mount a denial of service.
Category Archives: Debian
Debian Security Advisories
DSA-3638 curl – security update
Several vulnerabilities were discovered in cURL, an URL transfer library:
DSA-3637 chromium-browser – security update
Several vulnerabilities have been discovered in the chromium web browser.
DSA-3636 collectd – security update
Emilien Gaspar discovered that collectd, a statistics collection and
monitoring daemon, incorrectly processed incoming network
packets. This resulted in a heap overflow, allowing a remote attacker
to either cause a DoS via application crash, or potentially execute
arbitrary code.
DSA-3634 redis – security update
It was discovered that redis, a persistent key-value database, did not
properly protect redis-cli history files: they were created by default
with world-readable permissions.
DSA-3635 libdbd-mysql-perl – security update
Two use-after-free vulnerabilities were discovered in DBD::mysql, a Perl
DBI driver for the MySQL database server. A remote attacker can take
advantage of these flaws to cause a denial-of-service against an
application using DBD::mysql (application crash), or potentially to
execute arbitrary code with the privileges of the user running the
application.
DSA-3633 xen – security update
Multiple vulnerabilities have been discovered in the Xen hypervisor. The
Common Vulnerabilities and Exposures project identifies the following
problems:
DSA-3632 mariadb-10.0 – security update
Several issues have been discovered in the MariaDB database server. The
vulnerabilities are addressed by upgrading MariaDB to the new upstream
version 10.0.26. Please see the MariaDB 10.0 Release Notes for further
details:
DSA-3631 php5 – security update
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development.
DSA-3630 libgd2 – security update
Secunia Research at Flexera Software discovered an integer overflow
vulnerability within the _gdContributionsAlloc() function in libgd2, a
library for programmatic graphics creation and manipulation. A remote
attacker can take advantage of this flaw to cause a denial-of-service
against an application using the libgd2 library.