Category Archives: Debian

Debian Security Advisories

DSA-3578 libidn – security update

It was discovered that libidn, the GNU library for Internationalized
Domain Names (IDNs), did not correctly handle invalid UTF-8 input,
causing an out-of-bounds read. This could allow attackers to disclose
sensitive information from an application using the libidn library.

DSA-3577 jansson – security update

Gustavo Grieco discovered that jansson, a C library for encoding,
decoding and manipulating JSON data, did not limit the recursion depth
when parsing JSON arrays and objects. This could allow remote attackers
to cause a denial of service (crash) via stack exhaustion, using crafted
JSON data.

[BSA-110] Security Update for wordpress

Craig Small <csmall-8fiUuRrzOP0dnm+yROfE0A< at >public.gmane.org> uploaded new packages for wordpress
which fixed the following securty problems:

CVE-2016-4566 Reflected XSS in PLupload and mediaelement

For the jessie-backports distribution the problems have been fixed in
version 4.5.2+dfsg-1~bpo8+1

DSA-3574 libarchive – security update

Rock Stevens, Andrew Ruef and Marcin Icewall Noga discovered a
heap-based buffer overflow vulnerability in the zip_read_mac_metadata
function in libarchive, a multi-format archive and compression library,
which may lead to the execution of arbitrary code if a user or automated
system is tricked into processing a specially crafted ZIP file.