Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Microsoft wants consumers to control the camera by voice, according to filed patent
· Dell replays Windows 8 blame card as PC sales slide
· m23 rock 13.1 released
· Libreoffice 4.0.3 released and PPA installation instructions included
· MySQL 5.5.31 for Debian Squeeze
· Gigabyte Intel Z87 Motherboard Lineup Preview and more
· Microsoft to roll out Xbox dashboard UI alterations before next-gen console
· Adobe Photoshop Express now available for Windows 8 and RT
· GNOME 3.8.2 Released
· Windows 8 is an enterprise 'non-starter' because IT sees no value in changes

Upcoming News
· ARIA Gladiator 6300-HD7870LE AMD 4.10ghz 6 core System review
· Building a Thin Mini-ITX PC: Small and Silent Performance
· Fractal Design Arc Midi R2 Case @ Benchmark Reviews
· Mad Catz F.R.E.Q. 5 Gaming Headset Review @ Madshrimps
· HIS 7790 iCooler Turbo 1GB GDDR5 Video Card Review @ Madshrimps
· ROCCAT Hiro Mousepad Review @ OCC
· Crucial M500 480GB SSD Review
· NZXT H630 Ultra Tower Chassis Review
· Thermaltake Armor Revo Gene Mid Tower Computer Case Review @ Hi Tech Legion
· News: Gigabyte offers early peek at Z87 motherboards

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6349 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 646 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4503 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 709 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1098 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2012 » 3 Debian Updates

3 Debian Updates

Posted by Philipp Esselbach on: 12/12/2012 11:41 AM [ Print | 0 comment(s) ]

The following three security updates has been released for Debian GNU/Linux: [DSA 2586-1] perl security update, [DSA 2585-1] bogofilter security update, and [DSA 2587-1] libcgi-pm-perl security update




[DSA 2586-1] perl security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2586-1 security@debian.org
http://www.debian.org/security/
December 11, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : perl
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-5195 CVE-2012-5526
Debian Bug : 689314 693420 695223

Two vulnerabilities were discovered in the implementation of the Perl
programming language:

CVE-2012-5195
The "x" operator could cause the Perl interpreter to crash
if very long strings were created.

CVE-2012-5526
The CGI module does not properly escape LF characters
in the Set-Cookie and P3P headers.

In addition, this update adds a warning to the Storable documentation
that this package is not suitable for deserializing untrusted data.

For the stable distribution (squeeze), these problems have been fixed in
version 5.10.1-17squeeze4.

For the unstable distribution (sid), these problems have been fixed in
version 5.14.2-16.

We recommend that you upgrade your perl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

[DSA 2585-1] bogofilter security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2585-1 security@debian.org
http://www.debian.org/security/
December 11, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : bogofilter
Vulnerability : buffer overflow
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-5468
Debian Bug : 695139

A heap-based buffer overflow was discovered in bogofilter, a software
package for classifying mail messages as spam or non-spam. Crafted
mail messages with invalid base64 data could lead to heap corruption
and, potentially, arbitrary code execution.

For the stable distribution (squeeze), this problem has been fixed in
version 1.2.2-2+squeeze1.

For the testing distribution (wheezy) and the unstable distribution
(sid), this problem has been fixed in version 1.2.2+dfsg1-2.

We recommend that you upgrade your bogofilter packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

[DSA 2587-1] libcgi-pm-perl security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2587-1 security@debian.org
http://www.debian.org/security/
December 11, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libcgi-pm-perl
Vulnerability : HTTP header injection
Problem type : remote
Debian-specific: no
CVE ID : CVE-2012-5526
Debian Bug : 693421

It was discovered that the CGI module for Perl does not filter LF
characters in the Set-Cookie and P3P headers, potentially allowing
attackers to inject HTTP headers.

For the stable distribution (squeeze), this problem has been fixed in
version 3.49-1squeeze2.

For the unstable distribution (sid), this problem has been fixed in
version 3.61-2.

We recommend that you upgrade your libcgi-pm-perl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Bookmark and Share

« WD Red 3TB NAS Hard Drive Review · Intel Solid-State Drive DC S3700 Review »

Linux Compatible » News » December 2012 » 3 Debian Updates
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition