[SECURITY] [DLA 803-1] lcms2 security update

2017-01-26 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: lcms2 Version: 2.2+git20110628-2.2+deb7u2 CVE ID : CVE-2016-10165 Debian Bug : https://bugs.debian.org/852627 An out of bounds read was found in lcms2, which can lead to heap memory leak or denial of service via

[SECURITY] [DLA 802-1] openjdk-7 security update

2017-01-26 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: openjdk-7 Version: 7u121-2.6.8-1~deb7u1 openjdk-7 7u111-2.6.7-2~deb7u1 backported the security fixes from 7u121. openjdk-7 has now been updated to the full 7u121 version, which includes extra bug fixes and other

[SECURITY] [DLA 801-1] libxpm security update

2017-01-26 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libxpm Version: 1:3.5.10-1+deb7u1 CVE ID : CVE-2016-10164 Tobias Stoeckmann discovered a vulnerability in the libXpm library that could cause a malicious attacker to execute arbitrary code via a specially crafted

[SECURITY] [DLA 800-1] firefox-esr security update

2017-01-26 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: firefox-esr Version: 45.7.0esr-1~deb7u1 CVE ID : CVE-2017-5373 CVE-2017-5375 CVE-2017-5376 CVE-2017-5378 CVE-2017-5380 CVE-2017-5383 CVE-2017-5386 CVE-2017-5390 CVE-2017-5396