Brandon Perry discovered that xerces-c, a validating XML parser library
for C++, fails to successfully parse a DTD that is deeply nested,
causing a stack overflow. A remote unauthenticated attacker can take
advantage of this flaw to cause a denial of service against applications
using the xerces-c library.
Category Archives: Debian
Debian Security Advisories
DSA-3608 libreoffice – security update
Aleksandar Nikolic discovered that missing input sanitising in the RTF
parser in Libreoffice may result in the execution of arbitrary code if
a malformed documented is opened.
DSA-3607 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
DSA-3606 libpdfbox-java – security update
It was discovered that pdfbox, a PDF library for Java, was susceptible
to XML External Entity attacks.
DSA-3605 libxslt – security update
Several vulnerabilities were discovered in libxslt, an XSLT processing
runtime library, which could lead to information disclosure or
denial-of-service (application crash) against an application using the
libxslt library.
DSA-3604 drupal7 – security update
A privilege escalation vulnerability has been found in the User module
of the Drupal content management framework. For additional information,
please refer to the upstream advisory at
https://www.drupal.org/SA-CORE-2016-002.
DSA-3602 php5 – security update
Several vulnerabilities were found in PHP, a general-purpose scripting
language commonly used for web application development.
DSA-3603 libav – security update
Several security issues have been corrected in multiple demuxers and
decoders of the libav multimedia library. A full list of the changes is
available at
https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.7
DSA-3601 icedove – security update
Multiple security issues have been found in Icedove, Debian’s version of
the Mozilla Thunderbird mail client: Multiple memory safety errors may
lead to the execution of arbitrary code or denial of service.
DSA-3600 firefox-esr – security update
Multiple security issues have been found in the Mozilla Firefox web
browser: Multiple memory safety errors, buffer overflows and other
implementation errors may lead to the execution of arbitrary code or
spoofing.