Anton Rager and Jonathan Brossard from the Salesforce.com Product
Security Team and Ben Laurie of Google discovered a denial of service
vulnerability in xerces-c, a validating XML parser library for C++. The
parser mishandles certain kinds of malformed input documents, resulting
in a segmentation fault during a parse operation. An unauthenticated
attacker could use this flaw to cause an application using the
xerces-c library to crash.
Category Archives: Debian
Debian Security Advisories
DSA-3198 php5 – security update
Multiple vulnerabilities have been discovered in the PHP language:
DSA-3197 openssl – security update
Multiple vulnerabilities have been discovered in OpenSSL, a Secure
Sockets Layer toolkit. The Common Vulnerabilities and Exposures project
identifies the following issues:
DSA-3196 file – security update
Hanno Boeck discovered that file’s ELF parser is suspectible to denial
of service.
DSA-3195 php5 – security update
Multiple vulnerabilities have been discovered in the PHP language:
DSA-3193 tcpdump – security update
Several vulnerabilities have been discovered in tcpdump, a command-line
network traffic analyzer. These vulnerabilities might result in denial
of service (application crash) or, potentially, execution of arbitrary
code.
DSA-3194 libxfont – security update
Ilja van Sprundel, Alan Coopersmith and William Robinet discovered
multiple issues in libxfont’s code to process BDF fonts, which might
result in privilege escalation.
DSA-3192 checkpw – security update
Hiroya Ito of GMO Pepabo, Inc. reported that checkpw, a password
authentication program, has a flaw in processing account names which
contain double dashes. A remote attacker can use this flaw to cause a
denial of service (infinite loop).
DSA-3188 freetype – security update
Mateusz Jurczyk discovered multiple vulnerabilities in Freetype. Opening
malformed fonts may result in denial of service or the execution of
arbitrary code.
DSA-3191 gnutls26 – security update
Multiple vulnerabilities have been discovered in GnuTLS, a library
implementing the TLS and SSL protocols. The Common Vulnerabilities and
Exposures project identifies the following problems: