Blake Burkhart discovered an arbitrary code execution flaw in
Mercurial, a distributed version control system, when using the convert
extension on Git repositories with specially crafted names. This flaw in
particular affects automated code conversion services that allow
arbitrary repository names.
Category Archives: Debian
Debian Security Advisories
DSA-3569 openafs – security update
Two vulnerabilities were discovered in openafs, an implementation of the
distributed filesystem AFS. The Common Vulnerabilities and Exposures
project identifies the following problems:
DSA-3568 libtasn1-6 – security update
Pascal Cuoq and Miod Vallat discovered that Libtasn1, a library to
manage ASN.1 structures, does not correctly handle certain malformed DER
certificates. A remote attacker can take advantage of this flaw to cause
an application using the Libtasn1 library to hang, resulting in a denial
of service.
DSA-3567 libpam-sshauth – security update
It was discovered that libpam-sshauth, a PAM module to authenticate
using an SSH server, does not correctly handle system users. In certain
configurations an attacker can take advantage of this flaw to gain root
privileges.
DSA-3566 openssl – security update
Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer
toolkit.
DSA-3564 chromium-browser – security update
Several vulnerabilities have been discovered in the chromium web browser.
DSA-3565 botan1.10 – security update
Several security vulnerabilities were found in botan1.10, a C++
library which provides support for many common cryptographic
operations, including encryption, authentication, X.509v3 certificates
and CRLs.
DSA-3562 tardiff – security update
Several vulnerabilities were discovered in tardiff, a tarball comparison
tool. The Common Vulnerabilities and Exposures project identifies the
following problems:
DSA-3563 poppler – security update
It was discovered that a heap overflow in the Poppler PDF library may
result in denial of service and potentially the execution of arbitrary
code if a malformed PDF file is opened.
DSA-3561 subversion – security update
Several vulnerabilities were discovered in Subversion, a version control
system. The Common Vulnerabilities and Exposures project identifies the
following problems: