[SECURITY] [DSA 4588-1] python-ecdsa security update

2019-12-17 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian Security Advisory DSA-4588-1   secur...@debian.org
https://www.debian.org/security/   Sebastien Delafond
December 17, 2019 https://www.debian.org/security/faq
- -

Package: python-ecdsa
CVE ID : CVE-2019-14853 CVE-2019-14859

It was discovered that python-ecdsa, a cryptographic signature library
for Python, incorrectly handled certain signatures. A remote attacker
could use this issue to cause python-ecdsa to either not warn about
incorrect signatures, or generate exceptions resulting in a
denial-of-service.

For the oldstable distribution (stretch), these problems have been fixed
in version 0.13-2+deb9u1.

For the stable distribution (buster), these problems have been fixed in
version 0.13-3+deb10u1.

We recommend that you upgrade your python-ecdsa packages.

For the detailed security status of python-ecdsa please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-ecdsa

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-BEGIN PGP SIGNATURE-

iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAl34+5QACgkQEL6Jg/PV
nWThYAf+PH/Het1sH5n/p+JnC9ys9BjbJw/bUrXl0RYx812cWlVo4wWkAyjS9xD/
q0tR8Gx2wqAEauGa8Vy8H2hP8iW82+lCGlOoWNMqpVE+x1fwTLA8GCwH6f/UBrPC
5UJv06X6WYtrp3l3NKnq5IOR4QmWIVg3+gmrlm+6wC5NELwOCg0eH79vy+qtbc0w
7LaEI4IOi7yz11sXo7O0vu31S70EiwzRW6kyjlLfOrPN2OigiKYOkdAbWUocnSkR
Uy/LlLCYZry60wbUu9adOz/MOib2Bc9ARzskPrTPUQ0JgrZT1kiUIFU18mmVW9ym
qD3fYFLisZQT0hcu1C1D+UDfAVrpQQ==
=CvMQ
-END PGP SIGNATURE-



[SECURITY] [DSA 4587-1] ruby2.3 security update

2019-12-17 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian Security Advisory DSA-4587-1   secur...@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
December 17, 2019 https://www.debian.org/security/faq
- -

Package: ruby2.3
CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255

Several vulnerabilities have been discovered in the interpreter for the
Ruby language, which could result in unauthorized access by bypassing
intended path matchings, denial of service, or the execution of
arbitrary code.

For the oldstable distribution (stretch), these problems have been fixed
in version 2.3.3-1+deb9u7.

We recommend that you upgrade your ruby2.3 packages.

For the detailed security status of ruby2.3 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/ruby2.3

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-BEGIN PGP SIGNATURE-

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl34o91fFIAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Q5Bg//fOjMRcVQ6GUsbc0Qaj2t1HCmVR066U6fGrDzbd/7ofWIwzJMLYfdWrIs
T3S2W+vuz1sj2lCN8C8PS81Oz+nxg8GXEMd4XGPmmH++cORSizOHimN3DF3ezXKA
WanSLuTzP7dR9QCHO0AoVpLzL+P9s5xJOwhhWon+odr2y87XQqO2wIrwn/wRlroy
ShKS9EcJQUITJw/MUhE8PCyRc7qIjsDl8p4JG2wsCJU2VSaiKuryHDTMvGlKZgGR
C1TebMVjKmUahfcfga1Fd4P7AjiKirOsfRFoPsXmVRpdjWzXml8HdKOsLK93udw8
z1vEPhg1iJEzUKMapCjK3V32W//G+Mxsznt6a1TJ6RexhOsol+w6xoaHPeLuWbKH
rMJvyTXVF9kPpN4n3QbwGmyyyAhL9Gekq4S2IGrjcn8IsDaQiqIooqz7tFMCmWQ8
IFa260TvVuHQhwluOUJ/upfFsaspFRsRTtRXpx4wZmo0TuOZQZH71uw35xPBVjFr
OXH5hqqhit3g43w+Il5LRIGFEb/4ckLTTECLmAjqjEHDhfwIJgCpI7UxIcP5D1FE
+M9ckMorWQTYKB76IrW8cN4k6USVmApBtfmwUzCjK0lZ69dMLnOO4qrXaPTo4SR3
UXfUb5UxEdW6a7ZDfMRkyxkFFFnKBdJrxf+dFO564+4nmMvz+58=
=VHpf
-END PGP SIGNATURE-



[SECURITY] [DSA 4586-1] ruby2.5 security update

2019-12-17 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian Security Advisory DSA-4586-1   secur...@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
December 17, 2019 https://www.debian.org/security/faq
- -

Package: ruby2.5
CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255

Several vulnerabilities have been discovered in the interpreter for the
Ruby language, which could result in unauthorized access by bypassing
intended path matchings, denial of service, or the execution of
arbitrary code.

For the stable distribution (buster), these problems have been fixed in
version 2.5.5-3+deb10u1.

We recommend that you upgrade your ruby2.5 packages.

For the detailed security status of ruby2.5 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/ruby2.5

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-BEGIN PGP SIGNATURE-

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl34oDxfFIAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SixA//RivjIrvziyMZKMS30716X1kgB3M1eXpL/oKCISu59wU3/dyrO4r2pwUj
fcqmZs7PQp1iFKCiRr7ZijS2V4efeK9UxmuwxRzQYNXnVhgkngbMc5j4LG56T6sG
uf1Mu2bsAOWEWBEDHLOFwoNmza12VTgBwAHMaVgl7tIdJeu1iit7Xryz5XY6xSHB
IReUiafIidLQAy5621pARmRNPhgxrwsNeSbpm3Cf8BiPcZi0pDYssJWx89JnVYU2
f9nHkHrTOPwq7vwgZlBdRFkcflRCX6V5yp3IMO0GatPy2xTZ4QFgBzATy9ES7A9y
51UrubgbvF1sf0T0NFm3l+BiCpePWSbKWIDhKPVUTQrLpNzZUhED3apNpYPe0F+/
tRcRSQ9J2bnPCE+sx5oZu7HXmNZKntyCN0blc5MtSPodLKgVXq1D4/4fFVH1J51X
BH8D3du+chM/ty5b+yL9HJIhYu0mLmr7h3fMpy8kPAjfSXi+LELtp/pFrDrFmf4S
kz1qTumC098pw57QKG+OJKOmGeT2x3wzmdOHWlkMHGh0HYHY1pSPA60P7rOw+9uR
p7clYTtu07rWsGMmwWJmBcb/YxtASagdSxD2fI50mTkZfkd7Tu3j405lcXMizsGg
IOteqeKY4g4ngrVlHxHg1hcc2QlKlUpSOQFidbBCL5EsTc8HkIc=
=ERNm
-END PGP SIGNATURE-