Frediano Ziglio of Red Hat discovered several vulnerabilities in spice,
a SPICE protocol client and server library. A malicious guest can
exploit these flaws to cause a denial of service (QEMU process crash),
execute arbitrary code on the host with the privileges of the hosting
QEMU process or read and write arbitrary memory locations on the host.
Category Archives: Debian
Debian Security Advisories
DSA-3370 freetype – security update
It was discovered that FreeType did not properly handle some malformed
inputs. This could allow remote attackers to cause a denial of service
(crash) via crafted font files.
DSA-3369 zendframework – security update
Multiple vulnerabilities were discovered in Zend Framework, a PHP
framework:
DSA-3368 cyrus-sasl2 – security update
It was discovered that cyrus-sasl2, a library implementing the Simple
Authentication and Security Layer, does not properly handle certain
invalid password salts. A remote attacker can take advantage of this
flaw to cause a denial of service.
DSA-3367 wireshark – security update
Multiple vulnerabilities were discovered in the dissectors/parsers for
ZigBee, GSM RLC/MAC, WaveAgent, ptvcursor, OpenFlow, WCCP and in internal
functions which could result in denial of service.
DSA-3365 iceweasel – security update
Multiple security issues have been found in Iceweasel, Debian’s version
of the Mozilla Firefox web browser: Multiple memory safety errors,
integer overflows, buffer overflows, use-after-frees and other
implementation errors may lead to the execution of arbitrary code,
information disclosure or denial of service.
DSA-3366 rpcbind – security update
A remotely triggerable use-after-free vulnerability was found in
rpcbind, a server that converts RPC program numbers into universal
addresses. A remote attacker can take advantage of this flaw to mount a
denial of service (rpcbind crash).
DSA-3364 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation or denial of service.
DSA-3363 owncloud-client – security update
Johannes Kliemann discovered a vulnerability in ownCloud Desktop Client,
the client-side of the ownCloud file sharing services. The vulnerability
allows man-in-the-middle attacks in situations where the server is using
self-signed certificates and the connection is already established. If
the user in the client side manually distrusts the new certificate, the
file syncing will continue using the malicious server as valid.
DSA-3362 qemu-kvm – security update
Several vulnerabilities were discovered in qemu-kvm, a full
virtualization solution on x86 hardware.