[SECURITY] [DLA 815-1] ntfs-3g security update

2017-02-02 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: ntfs-3g Version: 1:2012.1.15AR.5-2.1+deb7u3 CVE ID : CVE-2017-0358 Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing

Wheezy update of libphp-phpmailer?

2017-02-02 Thread Guido Günther
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of libphp-phpmailer: https://security-tracker.debian.org/tracker/source-package/libphp-phpmailer Would you like to take care of this yourself? If yes, please follow

LTS Report for January 2017

2017-02-02 Thread Roberto C . Sánchez
For January I spent 12.5 hours as follows: * php5: multiple issues - CVE-2016-7125, CVE-2016-9137, CVE-2016-9138: researched and documented non-applicable or already fixed issues - CVE-2016-3141: picked up Raphaël's work in progress and based on his notes integrated/backported an

Accepted ntfs-3g 1:2012.1.15AR.5-2.1+deb7u3 (source amd64 all) into oldstable

2017-02-02 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Wed, 01 Feb 2017 19:51:36 +0100 Source: ntfs-3g Binary: ntfs-3g ntfs-3g-dbg ntfs-3g-dev ntfs-3g-udeb ntfsprogs Architecture: source amd64 all Version: 1:2012.1.15AR.5-2.1+deb7u3 Distribution: wheezy-security Urgency: medium