The authors of CUPS, the Common UNIX Printing System, have found apotential buffer overflow bug in the code of the CUPS daemon where itreads the names of attributes. This affects all versions of CUPS.
A vulnerability in the ldap server which could be exploited by remote attackers to delete attributes from an object even if those attributes were protected by ACLs.
There are two problems with the gzip archiving program; the first is a crash when an input file name is over 1020 characters, and the second is a buffer overflow that could be exploited if gzip is run on a server such as an FTP server.
There exist several signedness bugs within the rsync program which allow remote attackers to write 0-bytes to almost arbitrary stack-locations, therefore being able to control the program flow and obtaining a shell remotely.