USN-6613-1: Ceph vulnerability
Lucas Henry discovered that Ceph incorrectly handled specially crafted POST requests. An uprivileged user could use this to bypass Ceph's authorization checks and upload a...
USN-6612-1: TinyXML vulnerability
It was discovered that TinyXML incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted XML file,...
Multiple Vulnerabilities in Jenkins Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in Jenkins, the most severe of which could allow for remote code execution. Jenkins (Core) is an open source automation...
USN-6610-1: Firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to...
USN-6611-1: Exim vulnerability
It was discovered that Exim incorrectly handled certain requests. A remote attacker could possibly use a published exploitation technique to inject e-mail messages with a...
DSA-5610-1 redis – security update
Multiple security issues were discovered in Redis, a persistent key-value database, which could result in the execution of arbitrary code or ACL bypass. https://security-tracker.debian.org/tracker/DSA-5610-1 Read...
DSA-5609-1 slurm-wlm – security update
Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, denial of...
Re: Buffer Overflow in graphviz via via a crafted config6a file
Posted by Matthew Fernandez on Jan 27 More specifically, this issue is an out-of-bounds read. AFAICT the issue was actually introduced in Graphviz 2.36. It...
CVEs based on commit messages
Posted by Mark Esler on Jan 27 Dear Meng Rujie, In regards to your recent FD posts, are you requesting CVEs based on the presence...
Re: null pointer deference in nano via read_the_list()
Posted by Mark Esler on Jan 27 Hi Meng, In your recent mass posts to FD, are you reporting vulnerabilities or bug reports which have...