Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 17.25%
  • Veröffentlicht 07.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construc...

  • EPSS 42.93%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue ...

  • EPSS 13.96%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult...

  • EPSS 0.19%
  • Veröffentlicht 07.12.2017 02:29:13
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.

  • EPSS 9.18%
  • Veröffentlicht 06.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading...

  • EPSS 1.56%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote atta...

  • EPSS 1.16%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechan...

  • EPSS 1.24%
  • Veröffentlicht 06.12.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underflow and assertion failure for ...

  • EPSS 0.07%
  • Veröffentlicht 05.12.2017 23:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.

  • EPSS 3.04%
  • Veröffentlicht 05.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.