Two vulnerabilities were fixed in radicale, a CardDAV/CalDAV server.
Category Archives: Debian
Debian Security Advisories
DSA-3461 freetype – security update
Mateusz Jurczyk discovered multiple vulnerabilities in
Freetype. Opening malformed fonts may result in denial of service or
the execution of arbitrary code.
DSA-3459 mysql-5.5 – security update
Several issues have been discovered in the MySQL database server. The
vulnerabilities are addressed by upgrading MySQL to the new upstream
version 5.5.47. Please see the MySQL 5.5 Release Notes and Oracle’s
Critical Patch Update advisory for further details:
DSA-3456 chromium-browser – security update
Several vulnerabilities were discovered in the chromium web browser.
DSA-3455 curl – security update
Isaac Boukris discovered that cURL, an URL transfer library, reused
NTLM-authenticated proxy connections without properly making sure that
the connection was authenticated with the same credentials as set for
the new transfer. This could lead to HTTP requests being sent over the
connection authenticated as a different user.
DSA-3454 virtualbox – security update
Multiple vulnerabilities have been discovered in VirtualBox, an x86
virtualisation solution.
DSA-3458 openjdk-7 – security update
Several vulnerabilities have been discovered in OpenJDK, an
implementation of the Oracle Java platform, resulting in breakouts of
the Java sandbox, information disclosur, denial of service and insecure
cryptography.
DSA-3457 iceweasel – security update
Multiple security issues have been found in Iceweasel, Debian’s version
of the Mozilla Firefox web browser: Multiple memory safety errors and a
buffer overflow may lead to the execution of arbitrary code. In addition
the bundled NSS crypto library addresses the SLOTH attack on TLS 1.2.
DSA-3453 mariadb-10.0 – security update
Several issues have been discovered in the MariaDB database server. The
vulnerabilities are addressed by upgrading MariaDB to the new upstream
version 10.0.23. Please see the MariaDB 10.0 Release Notes for further
details:
DSA-3452 claws-mail – security update
DrWhax
of the Tails project reported that Claws Mail is missing
range checks in some text conversion functions. A remote attacker
could exploit this to run arbitrary code under the account of a user
that receives a message from them using Claws Mail.