Dawid Golunski from LegalHackers discovered that PHP Swift Mailer, a
mailing solution for PHP, did not correctly validate user input. This
allowed a remote attacker to execute arbitrary code by passing
specially formatted email addresses in specific email headers.
Category Archives: Debian
Debian Security Advisories
DSA-3768 openjpeg2 – security update
Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression /
decompression library, may result in denial of service or the execution
of arbitrary code if a malformed JPEG 2000 file is processed.
DSA-3766 mapserver – security update
It was discovered that mapserver, a CGI-based framework for Internet
map services, was vulnerable to a stack-based overflow. This issue
allowed a remote user to crash the service, or potentially execute
arbitrary code.
DSA-3767 mysql-5.5 – security update
Several issues have been discovered in the MySQL database server. The
vulnerabilities are addressed by upgrading MySQL to the new upstream
version 5.5.54, which includes additional changes, such as performance
improvements, bug fixes, new features, and possibly incompatible
changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical
Patch Update advisory for further details:
DSA-3765 icoutils – security update
Several programming errors in the wrestool tool of icoutils, a suite
of tools to create and extract MS Windows icons and cursors, allow
denial of service or the execution of arbitrary code if a malformed
binary is parsed.
DSA-3763 pdns-recursor – security update
Florian Heinz and Martin Kluge reported that pdns-recursor, a recursive
DNS server, parses all records present in a query regardless of whether
they are needed or even legitimate, allowing a remote, unauthenticated
attacker to cause an abnormal CPU usage load on the pdns server,
resulting in a partial denial of service if the system becomes
overloaded.
DSA-3764 pdns – security update
Multiple vulnerabilities have been discovered in pdns, an authoritative
DNS server. The Common Vulnerabilities and Exposures project identifies
the following problems:
DSA-3762 tiff – security update
Multiple vulnerabilities have been discovered in the libtiff library
and the included tools tiff2rgba, rgb2ycbcr, tiffcp, tiffcrop, tiff2pdf
and tiffsplit, which may result in denial of service, memory disclosure
or the execution of arbitrary code.
DSA-3761 rabbitmq-server – security update
It was discovered that RabbitMQ, an implementation of the AMQP
protocol, didn’t correctly validate MQTT (MQ Telemetry Transport)
connection authentication. This allowed anyone to login to an existing
user account without having to provide a password.
DSA-3760 ikiwiki – security update
Multiple vulnerabilities have been found in the Ikiwiki wiki compiler: