It was discovered that rebinding a receiver of a direct method handle
may allow a protected method to be accessed.
Category Archives: Debian
Debian Security Advisories
DSA-3400 lxc – security update
Roman Fiedler discovered a directory traversal flaw in LXC, the Linux
Containers userspace tools. A local attacker with access to a LXC
container could exploit this flaw to run programs inside the container
that are not confined by AppArmor or expose unintended files in the host
to the container.
DSA-3399 libpng – security update
Several vulnerabilities have been discovered in the libpng PNG library.
The Common Vulnerabilities and Exposures project identifies the
following problems:
DSA-3398 strongswan – security update
Tobias Brunner found an authentication bypass vulnerability in
strongSwan, an IKE/IPsec suite.
DSA-3397 wpa – security update
Several vulnerabilities have been discovered in wpa_supplicant and
hostapd. The Common Vulnerabilities and Exposures project identifies the
following problems:
DSA-3396 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a denial of service.
DSA-3395 krb5 – security update
Several vulnerabilities were discovered in krb5, the MIT implementation
of Kerberos. The Common Vulnerabilities and Exposures project identifies
the following problems:
DSA-3394 libreoffice – security update
Multiple vulnerabilities have been discovered in LibreOffice, a
full-featured office productivity:
DSA-3393 iceweasel – security update
Multiple security issues have been found in Iceweasel, Debian’s version
of the Mozilla Firefox web browser: Multiple memory safety errors,
integer overflows, buffer overflows and other implementation errors may
lead to the execution of arbitrary code, information disclosure or
denial of service.
DSA-3392 freeimage – security update
Pengsu Cheng discovered that FreeImage, a library for graphic image
formats, contained multiple integer underflows that could lead to a
denial of service: remote attackers were able to trigger a crash by
supplying a specially crafted image.