Enrico Zini discovered a vulnerability in Syntastic, an addonmodule for the Vim editor that runs a file through external checkersand displays any resulting errors. Config files were looked up in thecurrent working directory which could result in arbitraryshell code execution if a malformed source code file is opened.
More info:
https://www.debian.org/security/2018/dsa-4261
Several vulnerabilities were discovered in libsmpack, a library used tohandle Microsoft compression formats. A remote attacker could craftmalicious CAB, CHM or KWAJ files and use these flaws to cause a denialof service via application crash, or potentially execute arbitrary code.
More info:
https://www.debian.org/security/2018/dsa-4260
Multiple Zip Slip vulnerabilities. Security Advisory. Security Advisory Description. CVE-2018-1002200 plexus-archiver before ...
More info:
https://support.f5.com/csp/article/K64709522