[SECURITY] [DSA 4588-1] python-ecdsa security update
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4588-1 secur...@debian.org https://www.debian.org/security/ Sebastien Delafond December 17, 2019 https://www.debian.org/security/faq - - Package: python-ecdsa CVE ID : CVE-2019-14853 CVE-2019-14859 It was discovered that python-ecdsa, a cryptographic signature library for Python, incorrectly handled certain signatures. A remote attacker could use this issue to cause python-ecdsa to either not warn about incorrect signatures, or generate exceptions resulting in a denial-of-service. For the oldstable distribution (stretch), these problems have been fixed in version 0.13-2+deb9u1. For the stable distribution (buster), these problems have been fixed in version 0.13-3+deb10u1. We recommend that you upgrade your python-ecdsa packages. For the detailed security status of python-ecdsa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-ecdsa Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -BEGIN PGP SIGNATURE- iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAl34+5QACgkQEL6Jg/PV nWThYAf+PH/Het1sH5n/p+JnC9ys9BjbJw/bUrXl0RYx812cWlVo4wWkAyjS9xD/ q0tR8Gx2wqAEauGa8Vy8H2hP8iW82+lCGlOoWNMqpVE+x1fwTLA8GCwH6f/UBrPC 5UJv06X6WYtrp3l3NKnq5IOR4QmWIVg3+gmrlm+6wC5NELwOCg0eH79vy+qtbc0w 7LaEI4IOi7yz11sXo7O0vu31S70EiwzRW6kyjlLfOrPN2OigiKYOkdAbWUocnSkR Uy/LlLCYZry60wbUu9adOz/MOib2Bc9ARzskPrTPUQ0JgrZT1kiUIFU18mmVW9ym qD3fYFLisZQT0hcu1C1D+UDfAVrpQQ== =CvMQ -END PGP SIGNATURE-
[SECURITY] [DSA 4587-1] ruby2.3 security update
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4587-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso December 17, 2019 https://www.debian.org/security/faq - - Package: ruby2.3 CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255 Several vulnerabilities have been discovered in the interpreter for the Ruby language, which could result in unauthorized access by bypassing intended path matchings, denial of service, or the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed in version 2.3.3-1+deb9u7. We recommend that you upgrade your ruby2.3 packages. For the detailed security status of ruby2.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby2.3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -BEGIN PGP SIGNATURE- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl34o91fFIAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Q5Bg//fOjMRcVQ6GUsbc0Qaj2t1HCmVR066U6fGrDzbd/7ofWIwzJMLYfdWrIs T3S2W+vuz1sj2lCN8C8PS81Oz+nxg8GXEMd4XGPmmH++cORSizOHimN3DF3ezXKA WanSLuTzP7dR9QCHO0AoVpLzL+P9s5xJOwhhWon+odr2y87XQqO2wIrwn/wRlroy ShKS9EcJQUITJw/MUhE8PCyRc7qIjsDl8p4JG2wsCJU2VSaiKuryHDTMvGlKZgGR C1TebMVjKmUahfcfga1Fd4P7AjiKirOsfRFoPsXmVRpdjWzXml8HdKOsLK93udw8 z1vEPhg1iJEzUKMapCjK3V32W//G+Mxsznt6a1TJ6RexhOsol+w6xoaHPeLuWbKH rMJvyTXVF9kPpN4n3QbwGmyyyAhL9Gekq4S2IGrjcn8IsDaQiqIooqz7tFMCmWQ8 IFa260TvVuHQhwluOUJ/upfFsaspFRsRTtRXpx4wZmo0TuOZQZH71uw35xPBVjFr OXH5hqqhit3g43w+Il5LRIGFEb/4ckLTTECLmAjqjEHDhfwIJgCpI7UxIcP5D1FE +M9ckMorWQTYKB76IrW8cN4k6USVmApBtfmwUzCjK0lZ69dMLnOO4qrXaPTo4SR3 UXfUb5UxEdW6a7ZDfMRkyxkFFFnKBdJrxf+dFO564+4nmMvz+58= =VHpf -END PGP SIGNATURE-
[SECURITY] [DSA 4586-1] ruby2.5 security update
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4586-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso December 17, 2019 https://www.debian.org/security/faq - - Package: ruby2.5 CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255 Several vulnerabilities have been discovered in the interpreter for the Ruby language, which could result in unauthorized access by bypassing intended path matchings, denial of service, or the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in version 2.5.5-3+deb10u1. We recommend that you upgrade your ruby2.5 packages. For the detailed security status of ruby2.5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby2.5 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -BEGIN PGP SIGNATURE- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl34oDxfFIAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SixA//RivjIrvziyMZKMS30716X1kgB3M1eXpL/oKCISu59wU3/dyrO4r2pwUj fcqmZs7PQp1iFKCiRr7ZijS2V4efeK9UxmuwxRzQYNXnVhgkngbMc5j4LG56T6sG uf1Mu2bsAOWEWBEDHLOFwoNmza12VTgBwAHMaVgl7tIdJeu1iit7Xryz5XY6xSHB IReUiafIidLQAy5621pARmRNPhgxrwsNeSbpm3Cf8BiPcZi0pDYssJWx89JnVYU2 f9nHkHrTOPwq7vwgZlBdRFkcflRCX6V5yp3IMO0GatPy2xTZ4QFgBzATy9ES7A9y 51UrubgbvF1sf0T0NFm3l+BiCpePWSbKWIDhKPVUTQrLpNzZUhED3apNpYPe0F+/ tRcRSQ9J2bnPCE+sx5oZu7HXmNZKntyCN0blc5MtSPodLKgVXq1D4/4fFVH1J51X BH8D3du+chM/ty5b+yL9HJIhYu0mLmr7h3fMpy8kPAjfSXi+LELtp/pFrDrFmf4S kz1qTumC098pw57QKG+OJKOmGeT2x3wzmdOHWlkMHGh0HYHY1pSPA60P7rOw+9uR p7clYTtu07rWsGMmwWJmBcb/YxtASagdSxD2fI50mTkZfkd7Tu3j405lcXMizsGg IOteqeKY4g4ngrVlHxHg1hcc2QlKlUpSOQFidbBCL5EsTc8HkIc= =ERNm -END PGP SIGNATURE-