This update includes the changes in tzdata 2025a. Notable changes are: - - Paraguay adopts permanent -03 starting in spring 2024. - - Updated leap second list, which was set to expire by the end of . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4085-1
debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1070176 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3908-1
Charles Fol discovered that the iconv() function in the GNU C library is prone to a buffer overflow vulnerability when converting strings to the ISO-2022-CN-EXT character set, which may lead to denial of service (application crash) or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5673-1
Jurien de Jong discovered that the parsing of KeyInfo elements within the XMLTooling library may result in server-side request forgery. For the oldstable distribution (bullseye), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5432-1
The webkit2gtk update released as 5396-1 introduced a compatibility problem that caused Evolution to display e-mail incorrectly. Evolution has been updated to solve this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5396-2
It was discovered that Ghostscript, the GPL PostScript/PDF interpreter, is prone to a buffer overflow vulnerability in the (T)BCP encoding filters, which could result in the execution of arbitrary code if malformed document files are processed (despite the -dSAFER sandbox . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5383-1
A flaw was discovered in tang, a network-based cryptographic binding server, which could result in leak of private keys. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5025-1
Get the latest Linux and open source security news straight to your inbox.