Debian Security Annoucements

Syndicate content
Debian Security Advisories
Updated: 4 weeks 11 hours ago

DSA-1632 tiff - buffer underflow

Mon, 2008-08-25 23:00

Drew Yao discovered that libTIFF, a library for handling the Tagged Image File Format, is vulnerable to a programming error allowing malformed tiff files to lead to a crash or execution of arbitrary code.

Categories: OS Updates

DSA-1631 libxml2 - denial of service

Thu, 2008-08-21 23:00

Andreas Solberg discovered that libxml2, the GNOME XML library, could be forced to recursively evaluate entities, until available CPU and memory resources were exhausted.

Categories: OS Updates

DSA-1630 linux-2.6 - denial of service/information leak

Wed, 2008-08-20 23:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: OS Updates

DSA-1629 postfix - programming error

Mon, 2008-08-18 23:00

Sebastian Krahmer discovered that Postfix, a mail transfer agent, incorrectly checks the ownership of a mailbox. In some configurations, this allows for appending data to arbitrary files as root.

Categories: OS Updates

DSA-1628 pdns - DNS response spoofing

Sat, 2008-08-09 23:00

Brian Dowling discovered that the PowerDNS authoritative name server does not respond to DNS queries which contain certain characters, increasing the risk of successful DNS spoofing (CVE-2008-3337). This update changes PowerDNS to respond with SERVFAIL responses instead.

Categories: OS Updates