Debian LTS: DLA-2923-1: h2database security update

data:image/svg+xml,%3Csvg%20xmlns=%22https://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Security researchers of JFrog Security and Ismail Aydemir discovered two remote code execution vulnerabilities in the H2 Java SQL database engine which can be exploited through various attack vectors, most notably through the H2 Console and by loading custom classes from remote servers through

Debian LTS: DLA-2920-1: varnish security update

data:image/svg+xml,%3Csvg%20xmlns=%22https://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

James Kettle discovered that a request smuggling attack can be performed on HTTP/1 connections on Varnish servers, high-performance web accelerators. The smuggled request would be treated as an additional request by the Varnish server which may lead to information disclosure and cache poisoning.