Several vulnerabilities were discovered in the chromium web browser.
Category Archives: Debian
Debian Security Advisories
DSA-3038 libvirt – security update
Several vulnerabilities were discovered in Libvirt, a virtualisation
abstraction library. The Common Vulnerabilities and Exposures project
identifies the following problems:
DSA-3036 mediawiki – security update
It was discovered that MediaWiki, a wiki engine, did not sufficiently
filter CSS in uploaded SVG files, allowing for cross site scripting.
DSA-3037 icedove – security update
Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the
Mozilla Network Security Service library, embedded in Wheezy’s Icedove),
was parsing ASN.1 data used in signatures, making it vulnerable to a
signature forgery attack.
DSA-3033 nss – security update
Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS
(the Mozilla Network Security Service library) was parsing ASN.1 data
used in signatures, making it vulnerable to a signature forgery attack.
DSA-3035 bash – security update
Tavis Ormandy discovered that the patch applied to fix CVE-2014-6271
released in DSA-3032-1 for bash, the GNU Bourne-Again Shell, was
incomplete and could still allow some characters to be injected into
another environment (CVE-2014-7169). With this update prefix and suffix
for environment variable names which contain shell functions are added
as hardening measure.
DSA-3034 iceweasel – security update
Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS
(the Mozilla Network Security Service library, embedded in Wheezy’s
Iceweasel package), was parsing ASN.1 data used in signatures, making it
vulnerable to a signature forgery attack.
DSA-3032 bash – security update
Stephane Chazelas discovered a vulnerability in bash, the GNU
Bourne-Again Shell, related to how environment variables are
processed. In many common configurations, this vulnerability is
exploitable over the network, especially if bash has been configured
as the system shell.
DSA-3031 apt – security update
The Google Security Team discovered a buffer overflow vulnerability in
the HTTP transport code in apt-get. An attacker able to
man-in-the-middle a HTTP request to an apt repository can trigger the
buffer overflow, leading to a crash of the http
apt method binary, or
potentially to arbitrary code execution.
DSA-3030 mantis – security update
Multiple SQL injection vulnerabilities have been discovered in the Mantis
bug tracking system.