Category Archives: Debian

Debian Security Advisories

DSA-3651 rails – security update

Andrew Carpenter of Critical Juncture discovered a cross-site scripting
vulnerability affecting Action View in rails, a web application
framework written in Ruby. Text declared as HTML safe will not have
quotes escaped when used as attribute values in tag helpers.

DSA-3652 imagemagick – security update

This updates fixes many vulnerabilities in imagemagick: Various memory
handling problems and cases of missing or incomplete input sanitising
may result in denial of service or the execution of arbitrary code if
malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum,
PDB, DDS, DCM, EXIF, RGF or BMP files are processed.

DSA-3649 gnupg – security update

Felix Doerre and Vladimir Klebanov from the Karlsruhe Institute of
Technology discovered a flaw in the mixing functions of GnuPG’s random
number generator. An attacker who obtains 4640 bits from the RNG can
trivially predict the next 160 bits of output.