Skip navigation.
Home

Bollettini della sicurezza Debian (Debian Security Advisories)

Syndicate content
Debian Security Advisories
Updated: 1 hour 54 min ago

DSA-1634 wordnet - stack and heap overflows

Sun, 08/31/2008 - 22:00

Rob Holland discovered several programming errors in WordNet, an electronic lexical database of the English language. These flaws could allow arbitrary code execution when used with untrusted input, for example when WordNet is in use as a back end for a web application.

DSA-1633 slash - SQL Injection, Cross-Site Scripting

Sun, 08/31/2008 - 22:00

It has been discovered that Slash, the Slashdot Like Automated Storytelling Homepage suffers from two vulnerabilities related to insufficient input sanitation, leading to execution of SQL commands (CVE-2008-2231) and cross-site scripting (CVE-2008-2553).

DSA-1632 tiff - buffer underflow

Mon, 08/25/2008 - 22:00

Drew Yao discovered that libTIFF, a library for handling the Tagged Image File Format, is vulnerable to a programming error allowing malformed tiff files to lead to a crash or execution of arbitrary code.

DSA-1631 libxml2 - denial of service

Thu, 08/21/2008 - 22:00

Andreas Solberg discovered that libxml2, the GNOME XML library, could be forced to recursively evaluate entities, until available CPU and memory resources were exhausted.

DSA-1630 linux-2.6 - denial of service/information leak

Wed, 08/20/2008 - 22:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1629 postfix - programming error

Mon, 08/18/2008 - 22:00

Sebastian Krahmer discovered that Postfix, a mail transfer agent, incorrectly checks the ownership of a mailbox. In some configurations, this allows for appending data to arbitrary files as root.

DSA-1628 pdns - DNS response spoofing

Sat, 08/09/2008 - 22:00

Brian Dowling discovered that the PowerDNS authoritative name server does not respond to DNS queries which contain certain characters, increasing the risk of successful DNS spoofing (CVE-2008-3337). This update changes PowerDNS to respond with SERVFAIL responses instead.

DSA-1627 opensc - programming error

Sun, 08/03/2008 - 22:00

Chaskiel M Grundman discovered that opensc, a library and utilities to handle smart cards, would initialise smart cards with the Siemens CardOS M4 card operating system without proper access rights. This allowed everyone to change the card's PIN.

DSA-1626 httrack - buffer overflow

Thu, 07/31/2008 - 22:00

Joan Calvet discovered that httrack, a utility to create local copies of websites, is vulnerable to a buffer overflow potentially allowing to execute arbitrary code when passed excessively long URLs.

DSA-1625 cupsys - buffer overflows

Thu, 07/31/2008 - 22:00

Several remote vulnerabilities have been discovered in the Common Unix Printing System (CUPS). The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1624 libxslt - buffer overflows

Wed, 07/30/2008 - 22:00

Chris Evans discovered that a buffer overflow in the RC4 functions of libexslt may lead to the execution of arbitrary code.

DSA-1623 dnsmasq - DNS cache poisoning

Wed, 07/30/2008 - 22:00

Dan Kaminsky discovered that properties inherent to the DNS protocol lead to practical DNS cache poisoning attacks. Among other things, successful attacks can lead to misdirected web traffic and email rerouting.

DSA-1622 newsx - buffer overflow

Wed, 07/30/2008 - 22:00

It was discovered that newsx, an NNTP news exchange utility, was affected by a buffer overflow allowing remote attackers to execute arbitrary code via a news article containing a large number of lines starting with a period.

DSA-1621 icedove - several vulnerabilities

Sat, 07/26/2008 - 22:00

Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1620 python2.5 - several vulnerabilities

Sat, 07/26/2008 - 22:00

Several vulnerabilities have been discovered in the interpreter for the Python language. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1619 python-dns - DNS response spoofing

Sat, 07/26/2008 - 22:00

Multiple weaknesses have been identified in PyDNS, a DNS client implementation for the Python language. Dan Kaminsky identified a practical vector of DNS response spoofing and cache poisoning, exploiting the limited entropy in a DNS transaction ID and lack of UDP source port randomization in many DNS implementations. Scott Kitterman noted that python-dns is vulnerable to this predictability, as it randomizes neither its transaction ID nor its source port. Taken together, this lack of entropy leaves applications using python-dns to perform DNS queries highly susceptible to response forgery.

DSA-1618 ruby1.9 - several vulnerabilities

Fri, 07/25/2008 - 22:00

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems:

DSA-1616 clamav - denial of service

Fri, 07/25/2008 - 22:00

Damian Put discovered a vulnerability in the ClamAV anti-virus toolkit's parsing of Petite-packed Win32 executables. The weakness leads to an invalid memory access, and could enable an attacker to crash clamav by supplying a maliciously crafted Petite-compressed binary for scanning. In some configurations, such as when clamav is used in combination with mail servers, this could cause a system to "fail open," facilitating a follow-on viral attack.

DSA-1617 refpolicy - incompatible policy

Thu, 07/24/2008 - 22:00

In DSA-1603-1, Debian released an update to the BIND 9 domain name server, which introduced UDP source port randomization to mitigate the threat of DNS cache poisoning attacks (identified by the Common Vulnerabilities and Exposures project as CVE-2008-1447). The fix, while correct, was incompatible with the version of SELinux Reference Policy shipped with Debian Etch, which did not permit a process running in the named_t domain to bind sockets to UDP ports other than the standard 'domain' port (53). The incompatibility affects both the 'targeted' and 'strict' policy packages supplied by this version of refpolicy.

DSA-1615 xulrunner - several vulnerabilities

Tue, 07/22/2008 - 22:00

Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: