To display the most relevant entries to you in priority,
vote for the stories you are interested in
(  )
and reject those that you are not interested in
(  )
Debian Security -
19 hours and 47 minutes ago
pMoritz Jodeit discovered that ClamAV, an anti-virus solution, suffers from an off-by-one-error in
its VBA project file processing, leading to a heap-based buffer overflow and potentially arbitrary
code execution (a
href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5050CVE-2008-5050/a)./p
|
Debian Security -
1 days and 19 hours ago
pMorgan Todd discovered a cross-site scripting vulnerability in awstats, a log file analyzer,
involving the config request parameter (and possibly others; a
href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3714CVE-2008-3714/a)./p
|
Debian Security -
1 days and 19 hours ago
pPaul Szabo rediscovered a vulnerability in the File::Path::rmtree function of Perl. It was
possible to exploit a race condition to create setuid binaries in a directory tree or remove
arbitrary files when a process is deleting this tree. This issue was originally known as a
href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448CVE-2005-0448/a and a
href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452CVE-2004-0452/a, which were
addressed by DSA-696-1 and DSA-620-1. Unfortunately, they were reintroduced later./p
|
Debian Security -
2 days and 19 hours ago
pAn integer overflow has been discovered in the image validation code of cupsys, the Common UNIX
Printing System. An attacker could trigger this bug by supplying a malicious graphic that could
lead to the execution of arbitrary code./p
|
Debian Security -
3 days and 19 hours ago
pDmitry E. Oboukhov discovered that flamethrower creates predictable temporary filenames, which may
lead to a local denial of service through a symlink attack./p
|
Debian Security -
4 days and 19 hours ago
pJavier Fernandez-Sanguino Pena discovered that updatejail, a component of the chroot maintenance
tool Jailer, creates a predictable temporary file name, which may lead to local denial of service
through a symlink attack./p
|
Debian Security -
4 days and 19 hours ago
pMasako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL,
insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross
site scripting, provided that the user uses the Internet Explorer web browser./p
|
Debian Security -
5 days and 19 hours ago
pJulien Danjou and Peter De Wachter discovered that a buffer overflow in the XPM loader of Imlib2,
a powerful image loading and rendering library, might lead to arbitrary code execution./p
|
Debian Security -
5 days and 19 hours ago
pSeveral remote vulnerabilities have been discovered network traffic analyzer Wireshark. The Common
Vulnerabilities and Exposures project identifies the following problems:/p
|
Debian Security -
10 days and 19 hours ago
pSeveral remote vulnerabilities have been discovered in the Iceweasel webbrowser, an unbranded
version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the
following problems:/p
|
Debian Security -
10 days and 19 hours ago
pSeveral vulnerabilities have been discovered in Enscript, a converter from ASCII text to
Postscript, HTML or RTF. The Common Vulnerabilities and Exposures project identifies the following
problems:/p
|
Debian Security -
11 days and 19 hours ago
pSeveral remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL
applications. The Common Vulnerabilities and Exposures project identifies the following problems:/p
|
Debian Security -
12 days and 19 hours ago
pSteve Kemp discovered that hf, an amateur-radio protocol suite using a soundcard as a modem,
insecurely tried to execute an external command which could lead to the elevation of privileges for
local users./p
|
Debian Security -
15 days and 19 hours ago
pSeveral vulnerabilities have been discovered in the interpreter for the Python language. The
Common Vulnerabilities and Exposures project identifies the following problems:/p
|
Debian Security -
17 days and 19 hours ago
pSeveral vulnerabilities have been discovered in the GNOME XML library. The Common Vulnerabilities
and Exposures project identifies the following problems:/p
|
Debian Security -
22 days and 19 hours ago
pIt was discovered that a heap overflow in the CDDB retrieval code of libcdaudio, a library for
controlling a CD-ROM when playing audio CDs, may result in the execution of arbitrary code./p
|
Debian Security -
24 days and 19 hours ago
pIt was discovered that ekg, a console Gadu Gadu client performs insufficient input sanitising in
the code to parse contact descriptions, which may result in denial of service./p
|
Debian Security -
25 days and 19 hours ago
pSeveral vulnerabilities have been discovered in NET SNMP, a suite of Simple Network Management
Protocol applications. The Common Vulnerabilities and Exposures project identifies the following
problems:/p
|
Debian Security -
28 days and 19 hours ago
pA symlink traversal vulnerability was discovered in MySQL, a relational database server. The
weakness could permit an attacker having both CREATE TABLE access to a database and the ability to
execute shell commands on the database server to bypass MySQL access controls, enabling them to
write to tables in databases to which they would not ordinarily have access./p
|
Debian Security -
36 days and 19 hours ago
pSeveral vulnerabilities have been discovered in the OpenOffice.org office suite:/p
|
Debian Security -
39 days and 20 hours ago
pSeveral denial-of-service vulnerabilities have been discovered in the ClamAV anti-virus toolkit:/p
|
Debian Security -
42 days and 20 hours ago
pDan Kaminsky discovered that libspf2, an implementation of the Sender Policy Framework (SPF) used
by mail servers for mail filtering, handles malformed TXT records incorrectly, leading to a buffer
overflow condition (a
href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2469CVE-2008-2469/a)./p
|
Debian Security -
43 days and 20 hours ago
pColin Walters discovered that the dbus_signature_validate function in dbus, a simple interprocess
messaging system, is prone to a denial of service attack./p
|
Debian Security -
45 days and 20 hours ago
pSeveral local vulnerabilities have been discovered in the Common UNIX Printing System. The Common
Vulnerabilities and Exposures project identifies the following problems:/p
|
Debian Security -
45 days and 20 hours ago
pDmitry E. Oboukhov discovered that the qemu-make-debian-root script in qemu, fast processor
emulator, creates temporary files insecurely, which may lead/p
|
Debian Security -
49 days and 20 hours ago
pSeveral vulnerabilities have been discovered in the Linux kernel that may lead to a denial of
service, privilege escalation or a leak of sensitive data. The Common Vulnerabilities and Exposures
project identifies the following problems:/p
|
Debian Security -
51 days and 20 hours ago
pIt was discovered that libxml2, the GNOME XML library, didn't correctly handle long entity names.
This could allow the execution of arbitrary code via a malicious XML file./p
|
Debian Security -
52 days and 20 hours ago
pSeveral vulnerabilities have been discovered in the Linux kernel that may lead to a denial of
service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the
following problems:/p
|
Debian Security -
53 days and 20 hours ago
pSeveral vulnerabilities have been discovered in the interpreter for the Ruby language, which may
lead to denial of service and other security problems. The Common Vulnerabilities and Exposures
project identifies the following problems:/p
|
|