[SECURITY] [DLA 1714-1] libsdl2 security update

2019-03-13 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libsdl2 Version: 2.0.2+dfsg1-6+deb8u1 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577 CVE-2019-7578 CVE-2019-7635 CVE-2019-7636 CVE-2019-7

[SECURITY] [DLA 1713-1] libsdl1.2 security update

2019-03-13 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libsdl1.2 Version: 1.2.15-10+deb8u1 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577 CVE-2019-7578 CVE-2019-7635 CVE-2019-7636 CVE-2019-763

[SECURITY] [DLA 1712-1] libsndfile security update

2019-03-13 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libsndfile Version: 1.0.25-9.1+deb8u4 CVE ID : CVE-2019-3832 It was found that the fix for CVE-2018-19758 was incomplete. That has been addressed in this update. The description for CVE-2018-19758 follows: A hea

[SECURITY] [DLA 1711-1] systemd security update

2019-03-13 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: systemd Version: 215-17+deb8u11 CVE ID : CVE-2019-3815 Debian Bug : 924060 A memory leak was discovered in the backport of fixes for CVE-2018-16864 in systemd-journald. Function dispatch_message_real() in journa

[SECURITY] [DLA 1710-1] xmltooling security update

2019-03-13 Thread Ferenc Wágner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: xmltooling Version: 1.5.3-2+deb8u4 CVE ID : CVE-2019-9628 Debian Bug : 924346 Ross Geerlings discovered that the XMLTooling library didn't correctly handle exceptions on malformed XML declarations, which could re

[SECURITY] [DLA 1709-1] waagent security update

2019-03-13 Thread Bastian Blank
Package: waagent Version: 2.2.18-3~deb8u2 CVE ID : CVE-2019-0804 Francis McBratney discovered that the Windows Azure Linux Agent created swap files with world-readable permissions, resulting in information disclosure. For Debian 8 "Jessie", this problem has been fixed in v