Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1
Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.2.6-5+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6226-1
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6208-1
Louis Moureaux discovered that incorrect packet processing in the game server of Freeciv, a free clone of the turn based strategy game Civilization, could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 3.0.6-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6173-1
Clay Ver Valen discovered an integer overflow in the AES-GCM implementation of the Mozilla Network Security Service libraries. For the oldstable distribution (bookworm), this problem has been fixed in version 2:3.87.1-1+deb12u2. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6149-1
Vlatko Kosturjak discovered that BIND, a DNS server implementation, does not properly handle malformed BRID/HHIT records, which may result in denial of service (named daemon crash). For the oldstable distribution (bookworm), this problem has been fixed in version 1:9.18.44-1~deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6107-1
It was discovered that Request Tracker, an extensible trouble-ticket tracking system is prone to a CSV injection via ticket values with special characters that are exported to a TSV from search results. For the oldstable distribution (bookworm), this problem has been fixed in version 4.4.6+dfsg-1.1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6032-1
A buffer overflow was discovered in the MMS module of the VLC media player. For the oldstable distribution (bullseye), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5707-1
Get the latest Linux and open source security news straight to your inbox.