An integer overflow in the EXIF metadata parser has been fixed in the GStreamer media framework. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3824-1
A couple of security issues were discovered in ruby2.5, the Ruby interpreter, and are as follows - CVE-2021-33621 . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3450-1
Several issues were found in GRUB2's font handling code, which could result in crashes and potentially execution of arbitrary code. These could lead to by-pass of UEFI Secure Boot on affected systems. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3190-1
Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4582-1
DSA 4571-1 updated Thunderbird to the 68.x series, which is incompatible with the Enigmail release shipped in Debian Buster. For the stable distribution (buster), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4571-2
Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4535-1
Get the latest Linux and open source security news straight to your inbox.