[SECURITY] [DLA 1701-1] openssl security update

2019-03-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: openssl Version: 1.0.1t-1+deb8u11 CVE ID : CVE-2019-1559 Juraj Somorovsky, Robert Merget and Nimrod Aviram discovered a padding oracle attack in OpenSSL. If an application encounters a fatal protocol error and then

[SECURITY] [DLA 1696-1] ceph security update

2019-03-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: ceph Version: 0.80.7-2+deb8u3 CVE ID : CVE-2018-14662 CVE-2018-16846 Debian Bug : 921948 921947 Several vulnerabilities were discovered in Ceph, a distributed storage and file system. CVE-2018-14662 It was

[SECURITY] [DLA 1700-1] uw-imap security update

2019-03-01 Thread Roberto C . Sánchez
Package: uw-imap Version: 8:2007f~dfsg-4+deb8u1 CVE ID : CVE-2018-19518 Debian Bug : 914632 A vulnerability was discovered in uw-imap, the University of Washington IMAP Toolkit, that might allow remote attackers to execute arbitrary OS commands if the IMAP server name