Annonces récentes sur la sécurité Debian
DSA-1600 sympa - dos
It was discovered that sympa, a modern mailing list manager, would crash when processing certain types of malformed messages.
DSA-1599 dbus - programming error
Havoc Pennington discovered that DBus, a simple interprocess messaging system, performs insufficient validation of security policies, which might allow local privilege escalation.
DSA-1598 libtk-img - buffer overflow
It was discovered that a buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service and potentially the execution of arbitrary code.
DSA-1597 mt-daapd - multiple vulnerabilities
Three vulnerabilities have been discovered in the mt-daapd DAAP audio server (also known as the Firefly Media Server). The Common Vulnerabilities and Exposures project identifies the following three problems:
DSA-1596 typo3 - several vulnerabilities
Several remote vulnerabilities have been discovered in the TYPO3 content management framework.
DSA-1595 xorg-server - several vulnerabilities
Several local vulnerabilities have been discovered in the X Window system. The Common Vulnerabilities and Exposures project identifies the following problems:
DSA-1594 imlib2 - buffer overflows
Stefan Cornelius discovered two buffer overflows in Imlib's - a powerful image loading and rendering library - image loaders for PNM and XPM images, which may result in the execution of arbitrary code.
DSA-1593 tomcat5.5 - missing input sanitising
It was discovered that the Host Manager web application performed insufficient input sanitising, which could lead to cross-site scripting.
DSA-1592 linux-2.6 - heap overflow
Two vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution. The Common Vulnerabilities and Exposures project identifies the following problems:
DSA-1591 libvorbis - several vulnerabilities
Several local (remote) vulnerabilities have been discovered in libvorbis, a library for the Vorbis general-purpose compressed audio codec. The Common Vulnerabilities and Exposures project identifies the following problems:
DSA-1569 cacti - insufficient input sanitising
It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.
DSA-1568 b2evolution - insufficient input sanitising
"unsticky" discovered that b2evolution, a blog engine, performs insufficient input sanitising, allowing for cross site scripting.
DSA-1567 blender - buffer overrun
Stefan Cornelius discovered a vulnerability in the Radiance High Dynamic Range (HDR) image parser in Blender, a 3D modelling application. The weakness could enable a stack-based buffer overflow and the execution of arbitrary code if a maliciously-crafted HDR file is opened, or if a directory containing such a file is browsed via Blender's image-open dialog.
DSA-1566 cpio - programming error
Dmitry Levin discovered a vulnerability in path handling code used by the cpio archive utility. The weakness could enable a denial of service (crash) or potentially the execution of arbitrary code if a vulnerable version of cpio is used to extract or to list the contents of a maliciously crafted archive.
DSA-1565 linux-2.6 - several vulnerabilities
Several local vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:
DSA-1564 wordpress - multiple vulnerabilities
Several remote vulnerabilities have been discovered in wordpress, a weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems:
DSA-1563 asterisk - programming error
Joel R. Voss discovered that the IAX2 module of Asterisk, a free software PBX and telephony toolkit performs insufficient validation of IAX2 protocol messages, which may lead to denial of service.
DSA-1562 iceape - programming error
It was discovered that crashes in the JavaScript engine of Iceape, an unbranded version of the Seamonkey internet suite could potentially lead to the execution of arbitrary code.
DSA-1561 ldm - programming error
Christian Herzog discovered that within the Linux Terminal Server Project, it was possible to connect to X on any LTSP client from any host on the network, making client windows and keystrokes visible to that host.
DSA-1560 kronolith2 - insufficient input sanitising
"The-0utl4w" discovered that the Kronolith, calendar component for the Horde Framework, didn't properly sanitise URL input, leading to a cross-site scripting vulnerability in the add event screen.