[SECURITY] [DLA 1020-1] jetty security update

2017-07-09 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: jetty Version: 6.1.26-1+deb7u1 CVE ID : CVE-2017-9735 Debian Bug : 864898 It was discovered that Jetty, a Java servlet engine and webserver, was vulnerable to a timing attack which might reveal cryptographic

[SECURITY] [DLA 1019-1] phpldapadmin security update

2017-07-09 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: phpldapadmin Version: 1.2.2-5+deb7u1 CVE ID : CVE-2017-11107 Debian Bug : #867719 It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for

[SECURITY] [DLA 1018-1] sqlite3 security update

2017-07-09 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: sqlite3 Version: 3.7.13-1+deb7u4 CVE ID : CVE-2017-10989 Debian Bug : #867618 It was discovered that there was a heap-based buffer over-read vulnerability in SQLite, a lightweight database engine. The