Several issues have been discovered in the MariaDB database server. The
vulnerabilities are addressed by upgrading MariaDB to the new upstream
version 10.0.20. Please see the MariaDB 10.0 Release Notes for further
details:
Category Archives: Debian
Debian Security Advisories
DSA-3310 freexl – security update
It was discovered that an integer overflow in freexl, a library to parse
Microsoft Excel spreadsheets may result in denial of service if a
malformed Excel file is opened.
DSA-3308 mysql-5.5 – security update
Several issues have been discovered in the MySQL database server. The
vulnerabilities are addressed by upgrading MySQL to the new upstream
version 5.5.44. Please see the MySQL 5.5 Release Notes and Oracle’s
Critical Patch Update advisory for further details:
DSA-3309 tidy – security update
Fernando Muñoz discovered that invalid HTML input passed to tidy, an
HTML syntax checker and reformatter, could trigger a buffer overflow.
This could allow remote attackers to cause a denial of service (crash)
or potentially execute arbitrary code.
DSA-3307 pdns-recursor – security update
Toshifumi Sakaguchi discovered that the patch applied to pdns-recursor,
a recursive DNS server, fixing
CVE-2015-1868, was insufficient in some
cases, allowing remote attackers to cause a denial of service
(service-affecting CPU spikes and in some cases a crash).
DSA-3306 pdns – security update
Toshifumi Sakaguchi discovered that the patch applied to pdns, an
authoritative DNS server, fixing
CVE-2015-1868, was insufficient in
some cases, allowing remote attackers to cause a denial of service
(service-affecting CPU spikes and in some cases a crash).
DSA-3305 python-django – security update
Several vulnerabilities were discovered in Django, a high-level Python
web development framework:
DSA-3304 bind9 – security update
Breno Silveira Soares of Servico Federal de Processamento de Dados
(SERPRO) discovered that the BIND DNS server is prone to a denial of
service vulnerability. A remote attacker who can cause a validating
resolver to query a zone containing specifically constructed contents
can cause the resolver to terminate with an assertion failure, resulting
in a denial of service to clients relying on the resolver.
DSA-3303 cups-filters – security update
It was discovered that the texttopdf utility, part of cups-filters, was
susceptible to multiple heap-based buffer overflows due to improper
handling of print jobs with a specially crafted line size. This could
allow remote attackers to crash texttopdf or possibly execute arbitrary
code.
DSA-3302 libwmf – security update
Insufficient input sanitising in libwmf, a library to process Windows
metafile data, may result in denial of service or the execution of
arbitrary code if a malformed WMF file is opened.