Jann Horn discovered that the setuid-root mount.ecryptfs_private helper
in the ecryptfs-utils would mount over any target directory that the
user owns, including a directory in procfs. A local attacker could use
this flaw to escalate his privileges.
Category Archives: Debian
Debian Security Advisories
DSA-3451 fuse – security update
Jann Horn discovered a vulnerability in the fuse (Filesystem in
Userspace) package in Debian. The fuse package ships an udev rule
adjusting permissions on the related /dev/cuse character device, making
it world writable.
DSA-3449 bind9 – security update
It was discovered that specific APL RR data could trigger an INSIST
failure in apl_42.c and cause the BIND DNS server to exit, leading to a
denial-of-service.
DSA-3448 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation or denial-of-service.
DSA-3447 tomcat7 – security update
It was discovered that malicious web applications could use the
Expression Language to bypass protections of a Security Manager as
expressions were evaluated within a privileged code section.
DSA-3446 openssh – security update
The Qualys Security team discovered two vulnerabilities in the roaming
code of the OpenSSH client (an implementation of the SSH protocol
suite).
DSA-3442 isc-dhcp – security update
It was discovered that a maliciously crafted packet can crash any of
the isc-dhcp applications. This includes the DHCP client, relay, and
server application. Only IPv4 setups are affected.
DSA-3445 pygments – security update
Javantea discovered that pygments, a generic syntax highlighter, is
prone to a shell injection vulnerability allowing a remote attacker to
execute arbitrary code via shell metacharacters in a font name.
DSA-3443 libpng – security update
Several vulnerabilities have been discovered in the libpng PNG library.
The Common Vulnerabilities and Exposures project identifies the
following problems:
DSA-3444 wordpress – security update
Crtc4L discovered a cross-site scripting vulnerability in wordpress, a
web blogging tool, allowing a remote authenticated administrator to
compromise the site.