[SECURITY] [DLA 324-1] binutils security update

2015-10-01 Thread Ben Hutchings
Package: binutils Version: 2.20.1-16+deb6u2 CVE ID : CVE-2012-3509 Debian Bug : 688951 This update fixes several issues as described below. PR ld/12613 (no CVE assigned) Niranjan Hasabnis discovered that passing an malformed linker script to GNU ld, part of bi

[SECURITY] [DLA 323-1] fuseiso security update

2015-10-01 Thread Mike Gabriel
Package: fuseiso Version: 20070708-2+deb6u1 Debian Bug : #779047 The following two issues have recently been fixed in Debian LTS (squeeze) for the fuseiso package. Issue 1 An integer overflow, leading to a heap-based buffer overflow flaw was found in the way FuseISO,

[SECURITY] [DLA 322-1] commons-httpclient security update

2015-10-01 Thread Mike Gabriel
Package: commons-httpclient Version: 3.1-9+deb6u2 CVE ID : CVE-2015-5262 Trevin Beattie [1] discovered an issue where one could observe hanging threads in a multi-threaded Java application. After debugging the issue, it became evident that the hanging threads were caused by