The fix for CVE-2025-1094 included an error that caused the PQescapeLiteral and PQescapeIdentifier methods to ignore their length parameter, reading until the null terminating byte instead. That could cause unintended characters to be included on the output, . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4052-2
It was discovered that the fix for CVE-2023-27372 broke (de)activation of plugins with dependencies. For Debian 10 buster, this problem has been fixed in version . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3347-2
The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2338-2
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. . Package : json-c Version : 0.11-4+deb8u2 CVE ID : CVE-2020-12762 Debian Bug : 960326 The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. This follow-up version now uses an upstream sanctioned patch that was specifically published for json-c 0.11, rather than a self-backported patch. For Debian 8 "Jessie", this problem has been fixed in version 0.11-4+deb8u2. We recommend that you upgrade your json-c packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
The update for munin issued as DSA-3794-2 caused a regression leading to Perl warnings being appended to the munin-cgi-graph log file. Updated packages are now available to correct this issue. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3794-3
Get the latest Linux and open source security news straight to your inbox.