[SECURITY] [DLA 401-1] imlib2 security update

2016-01-24 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: imlib2 Version: 1.4.2-8+deb6u1 CVE ID : CVE-2014-9762 CVE-2014-9763 CVE-2014-9764 CVE-2014-9762 GIF loader: Fix segv on images without colormap CVE-2014-9763 Prevent division-by-zero crashes CVE-2014-9764

Fixing CVE-2014-9674 (freetype) in wheezy

2016-01-24 Thread Guido Günther
Dear security team, while looking into CVEs that are fixed in Jessie and Squeeze but not yet in Wheezy I came across: https://security-tracker.debian.org/tracker/CVE-2014-9674 Since the fix consists of several commits including a fix for CVE-2014-9673 (which already was fixed in the package)

Re: squeeze update of cakephp?

2016-01-24 Thread Dmitry Smirnov
On Sat, 23 Jan 2016 07:37:02 PM Thorsten Alteholz wrote: > the Debian LTS team would like to fix the security issues which are > currently open in the Squeeze version of cakephp: > https://security-tracker.debian.org/tracker/CVE-2015-8379 > > Would you like to take care of this yourself? > [...]