Michal Kowalczyk discovered that missing input sanitising in the
foomatic-rip print filter might result in the execution of arbitrary
commands.
Category Archives: Debian
Debian Security Advisories
DSA-3408 gnutls26 – security update
It was discovered that GnuTLS, a library implementing the TLS and SSL
protocols, incorrectly validates the first byte of padding in CBC modes.
A remote attacker can possibly take advantage of this flaw to perform a
padding oracle attack.
DSA-3409 putty – security update
A memory-corrupting integer overflow in the handling of the ECH (erase
characters) control sequence was discovered in PuTTY’s terminal
emulator. A remote attacker can take advantage of this flaw to mount a
denial of service or potentially to execute arbitrary code.
DSA-3410 icedove – security update
Multiple security issues have been found in Icedove, Debian’s version of
the Mozilla Thunderbird mail client: Multiple memory safety errors,
integer overflows, buffer overflows and other implementation errors may
lead to the execution of arbitrary code or denial of service.
DSA-3407 dpkg – security update
Hanno Boeck discovered a stack-based buffer overflow in the dpkg-deb
component of dpkg, the Debian package management system. This flaw could
potentially lead to arbitrary code execution if a user or an automated
system were tricked into processing a specially crafted Debian binary
package (.deb) in the old style Debian binary package format.
DSA-3406 nspr – security update
It was discovered that incorrect memory allocation in the NetScape
Portable Runtime library might result in denial of service or the
execution of arbitrary code.
DSA-3405 smokeping – security update
Tero Marttila discovered that the Debian packaging for smokeping
installed it in such a way that the CGI implementation of Apache httpd
(mod_cgi) passed additional arguments to the smokeping_cgi program,
potentially leading to arbitrary code execution in response to crafted
HTTP requests.
DSA-3404 python-django – security update
Ryan Butterfield discovered a vulnerability in the date template filter
in python-django, a high-level Python web development framework. A
remote attacker can take advantage of this flaw to obtain any secret in
the application’s settings.
DSA-3403 libcommons-collections3-java – security update
This update backports changes from the commons-collections 3.2.2 release
which disable the deserialisation of the functors classes unless the
system property org.apache.commons.collections.enableUnsafeSerialization
is set to true
. This fixes a vulnerability in unsafe applications
deserialising objects from untrusted sources without sanitising the
input data. Classes considered unsafe are: CloneTransformer, ForClosure,
InstantiateFactory, InstantiateTransformer, InvokerTransformer,
PrototypeCloneFactory, PrototypeSerializationFactory and WhileClosure.
DSA-3402 symfony – security update
Several vulnerabilities have been discovered in symfony, a framework to
create websites and web applications. The Common Vulnerabilities and
Exposures project identifies the following problems: