Several vulnerabilities have been fixed in the GNU C Library, glibc.
Category Archives: Debian
Debian Security Advisories
DSA-3480 eglibc – security update
Several vulnerabilities have been fixed in the GNU C Library, eglibc.
DSA-3479 graphite2 – security update
Multiple vulnerabilities have been found in the Graphite font rendering
engine which might result in denial of service or the execution of
arbitrary code if a malformed font file is processed.
DSA-3478 libgcrypt11 – security update
Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered
that the ECDH secret decryption keys in applications using the
libgcrypt11 library could be leaked via a side-channel attack.
DSA-3477 iceweasel – security update
Holger Fuhrmannek discovered that missing input sanitising in the
Graphite font rendering engine could result in the execution of arbitrary
code.
DSA-3476 postgresql-9.4 – security update
Several vulnerabilities have been found in PostgreSQL-9.4, a SQL
database system.
DSA-3475 postgresql-9.1 – security update
Several vulnerabilities have been found in PostgreSQL-9.1, a SQL
database system.
DSA-3474 libgcrypt20 – security update
Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered
that the ECDH secret decryption keys in applications using the
libgcrypt20 library could be leaked via a side-channel attack.
DSA-3473 nginx – security update
Several vulnerabilities were discovered in the resolver in nginx, a
small, powerful, scalable web/proxy server, leading to denial of service
or, potentially, to arbitrary code execution. These only affect nginx if
the resolver
directive is used in a configuration file.
DSA-3472 wordpress – security update
Two vulnerabilities were discovered in wordpress, a web blogging tool.
The Common Vulnerabilities and Exposures project identifies the
following problems: