Marcin Noga discovered an integer underflow in Lhasa, a lzh archive
decompressor, which might result in the execution of arbitrary code if
a malformed archive is processed.
Category Archives: Debian
Debian Security Advisories
DSA-3539 srtp – security update
Randell Jesup and the Firefox team discovered that srtp, Cisco’s
reference implementation of the Secure Real-time Transport Protocol
(SRTP), does not properly handle RTP header CSRC count and extension
header length. A remote attacker can exploit this vulnerability to crash
an application linked against libsrtp, resulting in a denial of service.
DSA-3537 imlib2 – security update
Several vulnerabilities were discovered in imlib2, an image
manipulation library.
DSA-3536 libstruts1.2-java – security update
It was discovered that libstruts1.2-java, a Java framework for MVC
applications, contains a bug in its multi-page validation code. This
allows input validation to be bypassed, even if MPV is not used
directly.
DSA-3538 libebml – security update
Several vulnerabilities were discovered in libebml, a library for
manipulating Extensible Binary Meta Language files.
DSA-3533 openvswitch – security update
Kashyap Thimmaraju and Bhargava Shastry discovered a remotely
triggerable buffer overflow vulnerability in openvswitch, a production
quality, multilayer virtual switch implementation. Specially crafted
MPLS packets could overflow the buffer reserved for MPLS labels in an
OVS internal data structure. A remote attacker can take advantage of
this flaw to cause a denial of service, or potentially, execution of
arbitrary code.
DSA-3534 dhcpcd – security update
Guido Vranken discovered several vulnerabilities in dhcpcd, a DHCP
client, which may result in denial of service.
DSA-3535 kamailio – security update
Stelios Tsampas discovered a buffer overflow in the Kamailio SIP proxy
which might result in the execution of arbitrary code.
DSA-3532 quagga – security update
Kostya Kortchinsky discovered a stack-based buffer overflow
vulnerability in the VPNv4 NLRI parser in bgpd in quagga, a BGP/OSPF/RIP
routing daemon. A remote attacker can exploit this flaw to cause a
denial of service (daemon crash), or potentially, execution of arbitrary
code, if bgpd is configured with BGP peers enabled for VPNv4.
DSA-3531 chromium-browser – security update
Several vulnerabilities have been discovered in the chromium web browser.