[Secure-testing-team] Bug#720632: znc: CVE-2013-2130: NULL pointer dereference vulnerabilities

2013-08-24 Thread Salvatore Bonaccorso
Package: znc Version: 1.0-4 Severity: important Tags: security upstream patch Hi, the following vulnerability was published for znc. CVE-2013-2130[0]: null pointer dereference in webadmin See references for additional information and a patch. This only affectes znc 1.0. If you fix the

[Secure-testing-team] Bug#720735: initramfs-tools: mkinitramfs uses ldd, which is insecure and generates core dumps

2013-08-24 Thread Vincent Lefevre
Package: initramfs-tools Version: 0.113 Severity: important Tags: security I've noticed that when running update-initramfs, a core dump was generated in the current directory, which is in itself a first bug. After looking at this problem with strace, I saw that this came from: /usr/bin/ldd