[SECURITY] [DLA 427-1] nss security update

2016-02-23 Thread Guido Günther
Package: nss Version: 3.12.8-1+squeeze14 CVE ID : CVE-2016-1938 The s_mp_div function in Mozilla Network Security Services (NSS) before 3.21, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leverag

[SECURITY] [DLA 426-1] libssh2 security update

2016-02-23 Thread Ben Hutchings
Package: libssh2 Version: 1.2.6-1+deb6u2 CVE ID : CVE-2016-0787 Andreas Schneider reported that libssh2, an SSH2 protocol implementation used by many applications, did not generate sufficiently long Diffie-Hellman secrets. This vulnerability could be exploited by an eavesd

[SECURITY] [DLA 425-1] libssh security update

2016-02-23 Thread Ben Hutchings
Package: libssh Version: 0.4.5-3+squeeze3 CVE ID : CVE-2016-0739 Aris Adamantiadis of the libssh team discovered that libssh, an SSH2 protocol implementation used by many applications, did not generate sufficiently long Diffie-Hellman secrets. This vulnerability could be e