Debian 10717 Published by Philipp Esselbach 0

A httpcomponents-client security update has been released for Debian GNU/Linux 9 LTS to address an issue where a malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Debian 10717 Published by Philipp Esselbach 0

A httpcomponents-client security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where a malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Debian 10717 Published by Philipp Esselbach 0

A rails security update has been released for Debian GNU/Linux 9 LTS to address a potential Cross-Site Scripting (XSS) vulnerability was found in rails, a ruby based MVC framework.

Debian 10717 Published by Philipp Esselbach 0

A eclipse-wtp security update has been released for Debian GNU/Linux 9 LTS to address an issue where a component of the Eclipse IDE, XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

Debian 10717 Published by Philipp Esselbach 0

A activemq security update has been released for Debian GNU/Linux 9 LTS to address an issue where it is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else.

Debian 10717 Published by Philipp Esselbach 0

A php5 security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where an attacker can forge a cookie.

Debian 10717 Published by Philipp Esselbach 0

A puma security update has been released for Debian GNU/Linux 9 LTS to address several security vulnerabilities in puma, a highly concurrent HTTP server for Ruby/Rack applications.

Debian 10717 Published by Philipp Esselbach 0

A tigervnc security update has been released for Debian GNU/Linux 9 LTS to address an issue where viewer implementation mishandles TLS certificate exceptions.

Debian 10717 Published by Philipp Esselbach 0

A xen security update has been released for Debian GNU/Linux 10 to address multiple vulnerabilities in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information leaks.

Debian 10717 Published by Philipp Esselbach 0

A snmptt security update has been released for Debian GNU/Linux 9 LTS to address an issue where a remote attacker can send a malicious crafted SNMP trap, which possibly execute arbitrary shell code with the privileges of the process or cause a Denial of Service condition.