Dean Rasheed discovered that row security policies in the PostgreSQLdatabase system could be bypassed.
More info:
https://www.debian.org/security/2019/dsa-4439
Multiple vulnerabilities were discovered in the Symfony PHP frameworkwhich could lead to cache bypass, authentication bypass, informationdisclosure, open redirect, cross-site request forgery, deletion ofarbitrary files, or arbitrary code execution.
More info:
https://www.debian.org/security/2019/dsa-4441
Multiple vulnerabilities were found in the BIND DNS server:
More info:
https://www.debian.org/security/2019/dsa-4440