[SECURITY] [DLA 978-1] perl security update

2017-06-05 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: perl Version: 5.14.2-21+deb7u5 CVE ID : CVE-2017-6512 Debian Bug : 863870 The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to c

[SECURITY] [DLA 976-1] yodl security update

2017-06-05 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: yodl Version: 3.00.0-6+deb7u1 CVE ID : CVE-2016-10375 Hanno Bock discovered that there was a buffer over-read vulnerability in the yodl ("Your Own Document Language") document processor. For Debian 7 "Wheezy", this

[SECURITY] [DLA 977-1] freeradius security update

2017-06-05 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: freeradius Version: 2.1.12+dfsg-1.2+deb7u1 CVE ID : CVE-2014-2015 CVE-2015-4680 CVE-2017-9148 Debian Bug : 742820 789623 863673 Several issues were discovered in FreeRADIUS, a high-performance and highly configur