debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2948-1
Access to IMAP mailboxes through running imapd over rsh and ssh is now disabled by default in uw-imap, the University of Washington IMAP Toolkit. Code using the library can enable it with tcp_parameters() after making sure that the IMAP server name is sanitized. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2866-1
A vulnerability was discovered in libimage-exiftool-perl, a library and program to read and write meta information in multimedia files, which may result in execution of arbitrary code if a malformed DjVu file is processed. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2663-1
It was discovered that Apache Tomcat from 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2495-1
Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server. For the oldstable distribution (stretch), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4582-1
Lilith of Cisco Talos discovered a buffer overflow flaw in the quota code used by e2fsck from the ext2/ext3/ext4 file system utilities. Running e2fsck on a malformed file system can result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4535-1
A cross-site scripting vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https:// . . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4434-1
It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4387-2
Get the latest Linux and open source security news straight to your inbox.