It was discovered that atril, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For Debian 11 bullseye, this problem has been fixed in version 1.24.0-1+deb11u2.
It was discovered that evince, a simple multi-page document viewer, is prone to a command injection vulnerability if a specially crafted PDF file is opened. For Debian 11 bullseye, this problem has been fixed in version 3.38.2-1+deb11u1.
Multiple vulnerabilities were found in GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, which may lead to constraint bypass, denial of service, information disclosure, authentication bypass or potentially execution of arbitrary code.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.11.0esr-1~deb11u1. We recommend that you upgrade your thunderbird packages.
A vulnerability was identified in uclouvain. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. For Debian 11 bullseye, this problem has been fixed in version 2.4.0-3+deb11u3.