[SECURITY] [DLA 723-1] libsoap-lite-perl security update

2016-11-25 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libsoap-lite-perl Version: 0.714-1+deb7u1 CVE ID : CVE-2015-8978 It was discovered that there was a "Billion Laughs" [0] XML expansion vulnerability in libsoap-lite-perl, a Perl implementation of a SOAP [1] client an

[SECURITY] [DLA 722-1] irssi security update

2016-11-25 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: irssi Version: 0.8.15-5+deb7u1 CVE ID : CVE-2016-7553 Debian Bug : 838762 An information disclosure vulnerability was found in irssi. CVE-2016-7553 Other users on the same machine as the user running irssi wit

[SECURITY] [DLA 721-1] libgc security update

2016-11-25 Thread Raphael Hertzog
Package: libgc Version: 1:7.1-9.1+deb7u1 CVE ID : CVE-2016-9427 Debian Bug : 844771 libgc is vulnerable to integer overflows in multiple places. In some cases, when asked to allocate a huge quantity of memory, instead of failing the request, it will return a pointer to