Advisory: Debian LTS Essential and Critical Security Patch Updates

Find the information you need for your favorite open source distribution .

Debian LTS: DLA-2926-1: zsh security update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

It was discovered that zsh, a powerful shell and scripting language, did not prevent recursive prompt expansion. This would allow an attacker to execute arbitrary commands into a user's shell, for instance by tricking a vcs_info user into checking out a git branch

Debian LTS: DLA-2923-1: h2database security update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Security researchers of JFrog Security and Ismail Aydemir discovered two remote code execution vulnerabilities in the H2 Java SQL database engine which can be exploited through various attack vectors, most notably through the H2 Console and by loading custom classes from remote servers through

Debian LTS: DLA-2920-1: varnish security update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

James Kettle discovered that a request smuggling attack can be performed on HTTP/1 connections on Varnish servers, high-performance web accelerators. The smuggled request would be treated as an additional request by the Varnish server which may lead to information disclosure and cache poisoning.