Security Advisories

TA10-040A: Microsoft Updates for Multiple Vulnerabilities

Microsoft Updates for Multiple Vulnerabilities
Categories: Security Advisories

DSA-2059 pcsc-lite - buffer overflow

Debian GNU/Linux - Thu, 06/10/2010 - 07:00

It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root.

Categories: Security Advisories

DSA-2058 glibc, eglibc - multiple vulnerabilities

Debian GNU/Linux - Thu, 06/10/2010 - 07:00

Several vulnerabilities have been discovered in the GNU C Library (aka glibc) and its derivatives. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security Advisories

TA10-021A: Microsoft Internet Explorer Vulnerabilities

Microsoft Internet Explorer Vulnerabilities
Categories: Security Advisories

TA10-013A: Adobe Reader and Acrobat Vulnerabilities

Adobe Reader and Acrobat Vulnerabilities
Categories: Security Advisories

DSA-2057 mysql-dfsg-5.0 - several vulnerabilities

Debian GNU/Linux - Mon, 06/07/2010 - 07:00

Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security Advisories

DSA-2056 zonecheck - missing input sanitizing

Debian GNU/Linux - Sun, 06/06/2010 - 07:00

It was discovered that in zonecheck, a tool to check DNS configurations, the CGI does not perform sufficient sanitation of user input; an attacker can take advantage of this and pass script code in order to perform cross-site scripting attacks.

Categories: Security Advisories

DSA-2055 openoffice.org - macro execution

Debian GNU/Linux - Sat, 06/05/2010 - 07:00

It was discovered that OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft® Office, is not properly handling python macros embedded in an office document. This allows an attacker to perform user-assisted execution of arbitrary code in certain use cases of the python macro viewer component.

Categories: Security Advisories

DSA-2054 bind9 - DNS cache poisoning

Debian GNU/Linux - Fri, 06/04/2010 - 07:00

Several cache-poisoning vulnerabilities have been discovered in BIND. These vulnerabilities apply only if DNSSEC validation is enabled and trust anchors have been installed, which is not the default.

Categories: Security Advisories

DSA-2053 linux-2.6 - privilege escalation/denial of service/information leak

Debian GNU/Linux - Tue, 05/25/2010 - 07:00

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security Advisories

DSA-2052 krb5 - null pointer dereference

Debian GNU/Linux - Mon, 05/24/2010 - 07:00

Shawn Emery discovered that in MIT Kerberos 5 (krb5), a system for authenticating users and services on a network, a null pointer dereference flaw in the Generic Security Service Application Program Interface (GSS-API) library could allow an authenticated remote attacker to crash any server application using the GSS-API authentication mechanism, by sending a specially-crafted GSS-API token with a missing checksum field.

Categories: Security Advisories

DSA-2051 postgresql-8.3 - several vulnerabilities

Debian GNU/Linux - Mon, 05/24/2010 - 07:00

Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems:

Categories: Security Advisories

DSA-2050 kdegraphics - several vulnerabilities

Debian GNU/Linux - Mon, 05/24/2010 - 07:00

Several local vulnerabilities have been discovered in KPDF, a PDF viewer for KDE, which allow the execution of arbitrary code or denial of service if a user is tricked into opening a crafted PDF document.

Categories: Security Advisories

DSA-2049 barnowl - buffer overflow

Debian GNU/Linux - Sun, 05/23/2010 - 07:00

It has been discovered that barnowl, a curses-based tty Jabber, IRC, AIM and Zephyr client, is prone to a buffer overflow via its "CC:" handling, which could lead to the execution of arbitrary code.

Categories: Security Advisories

DSA-2048 dvipng - buffer overflow

Debian GNU/Linux - Sat, 05/22/2010 - 07:00

Dan Rosenberg discovered that in dvipng, a utility that converts DVI files to PNG graphics, several array index errors allow context-dependent attackers, via a specially crafted DVI file, to cause a denial of service (crash of the application), and possibly arbitrary code execution.

Categories: Security Advisories
Syndicate content