[SECURITY] [DSA 4205-1] Advance notification for upcoming end-of-life for

2018-05-18 Thread Moritz Muehlenhoff
Debian oldstable

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian Security Advisory DSA-4205-1   secur...@debian.org
https://www.debian.org/security/   Moritz Muehlenhoff
May 18, 2018  https://www.debian.org/security/faq
- -

This is an advance notice that regular security support for Debian
GNU/Linux 8 (code name "jessie") will be terminated on the 17th of
June.

As with previous releases additional LTS support will be provided for
a reduced set of architectures and packages, a separate announcement
will be available in due time.

Mailing list: debian-security-announce@lists.debian.org
-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlr/JtkACgkQEMKTtsN8
TjZW+xAAmyEIgQwqVbL+cutQJiBpUWu+eRD+5eZ472yoiylD2qC42Kg8pacM2kZq
sHSszOqRzV7TgM7TficMgfai3tqyxwuVuffhZOythsxmxgQf6cJFoSP+pLGgwuxR
B07ua6PciAB+MHZIdPVI13fYMsyy4VSa9wcMewBjIWZWJDbVfPP56GTsI90JfscD
qZRHofxUQDkaXB6NMdZFcrxqU9W5SzlqW6XxUo/OulAtoZB80Q8c0QHn6GjF22nN
zBXbuMvgVAppD8hb4h6nK5OFzwNimVZBxhdndhdXbRq5dtT9BkkD3cXdaCycnQ9B
p125ju/6H8/izcf5WZ1CdZZnYdkIHU1Q4/LbBK772lTWFiYGMQ2EFosLM1lgk0BW
7JvV1CfkJe/2CRXb02FjyIN9klIek7EthgX+3XUdJIFuq2l6y+FY1qj8scgZ9bXu
J3Z8uciPybreQLdhHEyTlJ4/nmlR59Zgfsb5AQDETTXxvTGwVORPyaVrTceW5QKM
36ruVf5ZB832t8RGc+TClFb/xlW/YprbSgBJa+rlcKRNB/nPdzP2h/FIcxt+UVEJ
3YqSmew3xYgEQ1kwurdswl1/8AQeMo52DHtMCvBt9QqsSRlaAfN2RT9lqWefGuuX
Di/bia9I14U/MIxYxsGjgst7C1L0RC1v+lk4N51fXbgQCa4FE5U=
=9uO3
-END PGP SIGNATURE-



[SECURITY] [DSA 4204-1] imagemagick security update

2018-05-18 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian Security Advisory DSA-4204-1   secur...@debian.org
https://www.debian.org/security/   Sebastien Delafond
May 18, 2018  https://www.debian.org/security/faq
- -

Package: imagemagick
CVE ID : CVE-2017-10995 CVE-2017-11533 CVE-2017-11535 CVE-2017-11639 
 CVE-2017-13143 CVE-2017-17504 CVE-2017-17879 CVE-2018-5248
Debian Bug : 867748 869827 869834 870012 870065 885125 885340 886588

This update fixes several vulnerabilities in imagemagick, a graphical
software suite. Various memory handling problems or issues about
incomplete input sanitizing would result in denial of service or
memory disclosure.

For the oldstable distribution (jessie), these problems have been fixed
in version 8:6.8.9.9-5+deb8u12.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-BEGIN PGP SIGNATURE-

iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlr/BU8ACgkQEL6Jg/PV
nWTEIQf/YirH/RXDrvF4CRNZS3jPHCaNEmxXvvgs1tGTs04fQMPNdrEP2gZFfUnk
hu83t7GjUE+J1DAjjgtZQ9PQYPGhXidOaKHR6kTcUTENySl5V8PLkdF1EFK1M2Tn
CAd1TH4L5Q/2SFZnfBsu3KzpYOHWHSYl5BlJwwDznruGt7yAhHIGHP/RLRnlxJCx
uYUhM3PyU41CATeLCMX/owea3ND7Ro+ZpEKHy7KDcdx0WLx29yBU1wNN2+kxGsEc
ScHWGMFUMmTVeKtpfGF1rw5+8r6wgKiQoEzBPgSiXYLIDptTBTiS1rrBoy6hysXv
hi8jcwjII6qmrEqwTGjN1yMAnx/CWQ==
=UKUX
-END PGP SIGNATURE-