Советы по безопасности за 2013 год

[30.04.2013] DSA-2665 strongswan - authentication bypass
[22.04.2013] DSA-2663 tinc - stack based buffer overflow
[18.04.2013] DSA-2662 xen - several vulnerabilities
[17.04.2013] DSA-2661 xorg-server - information disclosure
[20.04.2013] DSA-2660 curl - exposure of sensitive information
[09.04.2013] DSA-2659 libapache-mod-security - XML external entity processing vulnerability
[04.04.2013] DSA-2658 postgresql-9.1 - several vulnerabilities
[04.04.2013] DSA-2657 postgresql-8.4 - guessable random numbers
[30.03.2013] DSA-2656 bind9 - denial of service
[28.03.2013] DSA-2655 rails - several vulnerabilities
[03.04.2013] DSA-2654 libxslt - denial of service
[26.03.2013] DSA-2653 icinga - buffer overflow
[24.03.2013] DSA-2652 libxml2 - external entity expansion
[20.03.2013] DSA-2651 smokeping - cross-site scripting vulnerability
[17.03.2013] DSA-2650 libvirt - files and device nodes ownership change to kvm group
[15.03.2013] DSA-2649 lighttpd - fixed socket name in world-writable directory
[15.03.2013] DSA-2648 firebird2.5 - several vulnerabilities
[15.03.2013] DSA-2647 firebird2.1 - buffer overflow
[15.03.2013] DSA-2646 typo3-src - several vulnerabilities
[14.03.2013] DSA-2645 inetutils - denial of service
[14.03.2013] DSA-2644 wireshark - several vulnerabilities
[12.03.2013] DSA-2643 puppet - several vulnerabilities
[09.03.2013] DSA-2642 sudo - several issues
[20.03.2013] DSA-2641 perl - rehashing flaw
[14.03.2013] DSA-2640 zoneminder - several issues
[05.03.2013] DSA-2639 php5 - several vulnerabilities
[04.03.2013] DSA-2638 openafs - buffer overflow
[04.03.2013] DSA-2637 apache2 - several issues
[03.03.2013] DSA-2636 xen - several vulnerabilities
[01.03.2013] DSA-2635 cfingerd - buffer overflow
[27.02.2013] DSA-2634 python-django - several vulnerabilities
[26.02.2013] DSA-2633 fusionforge - privilege escalation
[25.02.2013] DSA-2632 linux-2.6 - privilege escalation/denial of service
[24.02.2013] DSA-2631 squid3 - denial of service
[20.02.2013] DSA-2630 postgresql-8.4 - programming error
[25.02.2013] DSA-2629 openjpeg - several issues
[18.02.2013] DSA-2628 nss-pam-ldapd - buffer overflow
[17.02.2013] DSA-2627 nginx - information leak
[17.02.2013] DSA-2626 lighttpd - several issues
[17.02.2013] DSA-2625 wireshark - several vulnerabilities
[16.02.2013] DSA-2624 ffmpeg - several vulnerabilities
[14.02.2013] DSA-2623 openconnect - buffer overflow
[13.02.2013] DSA-2622 polarssl - several vulnerabilities
[13.02.2013] DSA-2621 openssl - several vulnerabilities
[12.02.2013] DSA-2620 rails - several vulnerabilities
[10.02.2013] DSA-2619 xen-qemu-dm-4.0 - buffer overflow
[07.02.2013] DSA-2618 ircd-hybrid - denial of service
[02.02.2013] DSA-2617 samba - several issues
[03.02.2013] DSA-2616 nagios3 - buffer overflow in CGI scripts
[01.02.2013] DSA-2615 libupnp4 - several vulnerabilities
[01.02.2013] DSA-2614 libupnp - several vulnerabilities
[29.01.2013] DSA-2613 rails - insufficient input validation
[10.02.2013] DSA-2612 ircd-ratbox - programming error
[22.01.2013] DSA-2611 movabletype-opensource - several vulnerabilities
[21.01.2013] DSA-2610 ganglia - arbitrary script execution
[16.01.2013] DSA-2609 rails - SQL query manipulation
[15.01.2013] DSA-2608 qemu - buffer overflow
[15.01.2013] DSA-2607 qemu-kvm - buffer overflow
[13.01.2013] DSA-2606 proftpd-dfsg - symlink race
[19.01.2013] DSA-2605 asterisk - several issues
[09.01.2013] DSA-2604 rails - insufficient input validation
[09.01.2013] DSA-2603 emacs23 - programming error
[08.01.2013] DSA-2602 zendframework - XML external entity inclusion
[06.01.2013] DSA-2601 gnupg, gnupg2 - missing input sanitation
[06.01.2013] DSA-2600 cups - privilege escalation
[06.01.2013] DSA-2599 nss - mis-issued intermediates
[05.01.2013] DSA-2598 weechat - several vulnerabilities
[04.01.2013] DSA-2597 rails - input validation error

Вы можете получать последние анонсы о безопасности в Debain, подписавшись на список рассылки debian-security-announce. Архив списка рассылки доступен здесь.