[SECURITY] [DLA 893-1] bouncycastle security update

2017-04-10 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bouncycastle Version: 1.44+dfsg-3.1+deb7u2 CVE ID : CVE-2015-6644 An information disclosure vulnerability was discovered in Bouncy Castle, a Java library which consists of various cryptographic algorithms. The

[SECURITY] [DLA 891-1] libnl security update

2017-04-10 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libnl Version: 1.1-7+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : It was discovered that there was a FIXME in libnl, a FIXME... For Debian 7 "Wheezy", this issue has been fixed in libnl version 1.1-7+deb7u1. We

[SECURITY] [DLA 892-1] libnl3 security update

2017-04-10 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libnl3 Version: 3.2.7-4+deb7u1 CVE ID : CVE-2017-0553 Debian Bug : #859948 It was discovered that there was an integer overflow in libnl3, a library for dealing with netlink sockets. A missing check in

[SECURITY] [DLA 890-1] ming security update

2017-04-10 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: ming Version: 1:0.4.4-1.1+deb7u2 CVE ID : CVE-2017-7578 It was discovered that there were multiple heap-based buffer overflows in ming, a library to generate SWF (Flash) files. The updated packages prevent a crash