[SECURITY] [DLA 2117-1] zsh security update

2020-03-02 Thread Roberto C . Sánchez
Package: zsh Version: 5.0.7-5+deb8u1 CVE ID : CVE-2019-20044 Debian Bug : 951458 A privilege escalation vulnerability was discovered in zsh, a shell with lots of features, whereby a user could regain a formerly elevated privelege level even when such an action should

[SECURITY] [DLA 2131-2] rrdtool regression update

2020-03-02 Thread Utkarsh Gupta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: rrdtool Version: 1.4.8-1.2+deb8u2 CVE ID : CVE-2014-6262 Debian Bug : 952958 It was discovered that there was a regression in a previous fix, which resulted in the following error: ERROR: cannot compile

[SECURITY] [DLA 2115-2] proftpd-dfsg regression update

2020-03-02 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: proftpd-dfsg Version: 1.3.5e+r1.3.5-2+deb8u7 CVE ID : CVE-2020-9273 It was discovered that there was a regression in a previous fix for a use-after-free vulnerability in the proftpd-dfsg FTP server. Exploitation of