Debian: DSA-5414-1: docker-registry security update
Jose Gomez discovered that the Catalog API endpoint in the Docker registry implementation did not sufficiently enforce limits, which could result in denial of service.
Find the information you need for your favorite open source distribution .
Jose Gomez discovered that the Catalog API endpoint in the Docker registry implementation did not sufficiently enforce limits, which could result in denial of service.
Multiple issues were found in GPAC multimedia framework, whcih could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in
An issue has been found in sniproxy, a transparent TLS and HTTP layer 4 proxy with SNI support. Due to bad handling of wildcard backend hosts, a crafted HTTP or TLS packet might lead to remote arbitrary code execution.
Multiple security issues were discovered in Sofia-SIP, a SIP User-Agent library, which could result in denial of service. For the stable distribution (bullseye), these problems have been fixed in
Two security issues have been discovered in libssh, a tiny C SSH library: CVE-2023-1667
Irvan Kurniawan discovered a double free in the libwebp image compression library which may result in denial of service. For the stable distribution (bullseye), this problem has been fixed in
It was discovered that missing input sanitising in cups-filters, when using the Backend Error Handler (beh) backend to create an accessible network printer, may result in the execution of arbitrary commands.
Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed.
It was discovered that missing input sanitising in the implementation of the OIDCStripCookie option in mod_auth_openidc could result in denial of service.