Category Archives: Debian

Debian Security Advisories

DSA-3749 dcmtk – security update

Gjoko Krstic of Zero Science Labs discovered that dcmtk, a collection
of libraries implementing the DICOM standard, did not properly handle
the size of data received from the network. This could lead to
denial-of-service (via application crash) or arbitrary code execution.

DSA-3745 squid3 – security update

Saulius Lapinskas from Lithuanian State Social Insurance Fund Board
discovered that Squid3, a fully featured web proxy cache, does not
properly process responses to If-None-Modified HTTP conditional
requests, leading to client-specific Cookie data being leaked to other
clients. A remote attacker can take advantage of this flaw to discover
private and sensitive information about another clients browsing
session.

DSA-3744 libxml2 – security update

Several vulnerabilities were discovered in libxml2, a library providing
support to read, modify and write XML and HTML files. A remote attacker
could provide a specially crafted XML or HTML file that, when processed
by an application using libxml2, would cause a denial-of-service against
the application, or potentially, the execution of arbitrary code with
the privileges of the user running the application.

DSA-3741 tor – security update

It was discovered that Tor, a connection-based low-latency anonymous
communication system, may read one byte past a buffer when parsing
hidden service descriptors. This issue may enable a hostile hidden
service to crash Tor clients depending on hardening options and malloc
implementation.