Debian 10966 Published by Philipp Esselbach 0

A spamassassin security update has been released for both Debian GNU/Linux 9 and 10 to address two vulnerabilities where malicious rule or configuration files could execute arbitrary
commands under multiple scenarios.

Debian 10966 Published by Philipp Esselbach 0

A firefox-esr security update has been released for Debian GNU/Linux 8 LTS to address an issue was found in the IonMonkey JIT compiler of the Mozilla Firefox web browser which could lead to arbitrary code execution.

Debian 10966 Published by Philipp Esselbach 0

A prosody-modules security update has been released for both Debian GNU/Linux 9 and 10 to address an issue where the Prosody Jabber/XMPP server incorrectly validated the XMPP address when checking whether a user has admin access.

Debian 10966 Published by Philipp Esselbach 0

A libsolv security update has been released for Debian GNU/Linux 8 LTS to address a heap-based buffer over-read via a last schema whose length could be less than the length of the input schema.

Debian 10966 Published by Philipp Esselbach 0

A qemu security update has been released for Debian GNU/Linux 8 LTS to address a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

Debian 10966 Published by Philipp Esselbach 0

A suricata security update has been released for Debian GNU/Linux 8 LTS to address two vulnerabilities in the stream-tcp code of the intrusion detection and prevention tool Suricata.

Debian 10966 Published by Philipp Esselbach 0

A libxmlrpc3-java security update for Debian GNU/Linux 8 LTS to address an untrusted deserialization in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library.

Debian 10966 Published by Philipp Esselbach 0

A zlib security update has been released for Debian GNU/Linux 7 Extended LTS to address improper big-endian CRC calculation, improper left shift of negative integers and improper pointer arithmetic.