The InCommon Shibboleth Training team discovered that XMLTooling, a
C++ XML parsing library, did not properly handle an exception when
parsing well-formed but schema-invalid XML. This could allow remote
attackers to cause a denial of service (crash) via crafted XML data.
Category Archives: Debian
Debian Security Advisories
DSA-3320 openafs – security update
It was discovered that OpenAFS, the implementation of the distributed
filesystem AFS, contained several flaws that could result in
information leak, denial-of-service or kernel panic.
DSA-3319 bind9 – security update
Jonathan Foote discovered that the BIND DNS server does not properly
handle TKEY queries. A remote attacker can take advantage of this flaw
to mount a denial of service via a specially crafted query triggering an
assertion failure and causing BIND to exit.
DSA-3318 expat – security update
Multiple integer overflows have been discovered in Expat, an XML parsing
C library, which may result in denial of service or the execution of
arbitrary code if a malformed XML file is processed.
DSA-3317 lxc – security update
Several vulnerabilities have been discovered in LXC, the Linux
Containers userspace tools. The Common Vulnerabilities and Exposures
project identifies the following problems:
DSA-3316 openjdk-7 – security update
Several vulnerabilities have been discovered in OpenJDK, an
implementation of the Oracle Java platform, resulting in the execution
of arbitrary code, breakouts of the Java sandbox, information disclosure,
denial of service or insecure cryptography.
DSA-3313 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation or denial of service.
DSA-3314 typo3-src – end of life
Upstream security support for Typo3 4.5.x ended three months ago and the
same now applies to the Debian packages as well.
DSA-3315 chromium-browser – security update
Several vulnerabilities were discovered in the chromium web browser.
DSA-3312 cacti – security update
Multiple SQL injection vulnerabilities were discovered in cacti, a web
interface for graphing of monitoring systems.