[SECURITY] [DLA 1125-1] botan1.10 security update

2017-10-06 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: botan1.10 Version: 1.10.5-1+deb7u4 CVE ID : CVE-2017-14737 CVE-2017-14737 Fix of cache-based side channel attack, which could recover information about RSA secret keys. For Debian 7 "Wheezy", these prob

[SECURITY] [DLA 1124-1] dnsmasq security update

2017-10-06 Thread Ben Hutchings
Package: dnsmasq Version: 2.62-3+deb7u4 CVE ID : CVE-2017-14491 CVE-2017-14492 CVE-2017-14494 Felix Wilhelm, Fermin J. Serna, Gabriel Campana, Kevin Hamacher, Ron Bowes and Gynvael Coldwind of the Google Security Team discovered several vulnerabilities in dnsmasq, a small c

[SECURITY] [DLA 1123-1] golang security update

2017-10-06 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: golang Version: 2:1.0.2-1.1+deb7u1 CVE ID : CVE-2017-198 It was discovered that there was an issue in the Go programming language library where an attacker could generate a MIME request such that the server ran o