[SECURITY] [DLA 2452-1] libdatetime-timezone-perl new upstream version

2020-11-15 Thread Adrian Bunk
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian LTS Advisory DLA-2452-1debian-...@lists.debian.org
https://www.debian.org/lts/security/  Adrian Bunk
November 16, 2020 https://wiki.debian.org/LTS
- -

Package: libdatetime-timezone-perl
Version: 1:2.09-1+2020d

This update includes the changes in tzdata 2020d for the
Perl bindings. For the list of changes, see DLA-2424-1.

For Debian 9 stretch, this problem has been fixed in version
1:2.09-1+2020d.

We recommend that you upgrade your libdatetime-timezone-perl packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAl+xt80ACgkQiNJCh6LY
mLHaKBAAi2FwVxbZ1cwZ6MbngPNkwDARXU7h0awjFCH1igyy+zFB9L1Kbrw6zkHx
V88yss4gbnsbHWozM9wWzn/qFvP+jgSkAD5Z8MmS3SL11Wxo0eC7S2WQQ0mdk88W
j9rMIwqTzYMRtKHuPBfrMo2ek3IJlNvY0ew3HC7fF8x1YDVzO2CqEEQF2slSt/qC
LiUsIm7JU28yJYr2GnvGG9uhaMA3TCqA+4nN/rCTvl7FdtQ/dbdFFQpxCYCk2Eye
R7sNCiJGHxxKlTDAj/ESdZDTINmUy06gE8eUwwTmd0md2wr1aETs1X+kOcWsyjW5
VWWdkouo6ksOg845j2KTCcZlEte6NzKZSBSf/mc66+wGCqKq1IeWiG4oaJ51WelA
963q3094oxiqsd7mViKLAYgQqmJ/atLaotgQiyQhLE3miryK1QnXzVEsQ7QFu08Y
fKN1zM4P78hPTGC9aqu/y5He3u+v0snNQD7lGHN/4WtsX3L1tPtGLJDv+4GLWbEV
Zs/jDHZixuWOKSRBlIveX8AVQzDglbqW2eTOy4vlasSJLEJFI6uaBi61PNbOHhob
SAcDPLOg/y83HMhiWebhLrBdbA07h6MmTOiiJ/EnOSMbnU77JbkEUpqd925xHau9
m4LFT4kg6tFYSfb7eJhWboCVFT8uhvTgAG6zs1midJHBCh9xrTY=
=kNXS
-END PGP SIGNATURE-



[SECURITY] [DLA 2451-1] libvncserver security update

2020-11-15 Thread Thorsten Alteholz

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian LTS Advisory DLA-2451-1debian-...@lists.debian.org
https://www.debian.org/lts/security/Thorsten Alteholz
November 15, 2020 https://wiki.debian.org/LTS
- -

Package: libvncserver
Version: 0.9.11+dfsg-1.3~deb9u6
CVE ID : CVE-2020-25708


An issue has been found in libvncserver, an API to write one's own VNC 
server.
Due to some missing checks, a divide by zero could happen, which could 
result in a denial of service.



For Debian 9 stretch, this problem has been fixed in version
0.9.11+dfsg-1.3~deb9u6.

We recommend that you upgrade your libvncserver packages.

For the detailed security status of libvncserver please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libvncserver

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-BEGIN PGP SIGNATURE-

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl+xnOtfFIAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEd07BAAhZnmzl/BVVJIaz2qWnqxTyPOheS8DwNq6DdJk34ZbDcfiOr9tkeYwVdU
qOTchNcYkm3oAmUv6P/OS0abVnvC2AH9GkV8tbFE8zuC7X7zn1LqJbe/tu4m159z
vYGtQLcV5oTDJ6zCYhDL6OobDcF/TMnBsqYzHE2yyjJ7b4OyquIas87gWGlMJaIr
Lb2bT4lLusrOzc2aiMPi7YFB2Abj+zSOoeg3Xl0w/orqwFIpZPjfgFwFHa/zT+C0
07H/syEktsUyo1NFYAsCmU7l6eTmjWT5lxdWKtDxVnj3sBxXJUj0S3QlelYYo+e4
xu9jkiJduN39CAiniWLfQaXQ7uhAKIPznfDsa4O7Iu3o69WzgQMSEikzfLHsm/B7
gakk8wXsDbx3xalpKr6mPNSyI/O00edpjqKSGC/nzdcid75MglNIWxJ1Lc6fcfQB
8QsGn1/1jsduXkyb/hC6gdupyf/cxdUmvTZDnlwpxoi3uNs4JrTu5r2rA/tVGlUZ
oBvkUP6IH0LcGchQxlbKt+R51KwUiR2hYbxK8becVTROZlYuOfWuBM3FK+j+SCTc
YYiXfbqwjIU/uHTiB2vsFmaxjQhBEs+dWV//Bs4tZ8bhuiv4xBPQekY9oWzuImCK
uGAuLBWuYJ8lbkQkGCyNVSUDRFVuxZxx823ATQR8Am5PvB740J8=
=lA2A
-END PGP SIGNATURE-