[SECURITY] [DLA 2167-1] python-bleach security update

2020-04-01 Thread Roberto C . Sánchez
Package: python-bleach Version: 1.4-1+deb8u1 CVE ID : CVE-2020-6817 Debian Bug : 955388 A vulnerability was discovered in python-bleach, a whitelist-based HTML-sanitizing library. Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable

[SECURITY] [DLA 2166-1] libpam-krb5 security update

2020-04-01 Thread Utkarsh Gupta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libpam-krb5 Version: 4.6-3+deb8u1 CVE ID : CVE-2020-10595 The krb5 PAM module (pam_krb5.so) had a buffer overflow that might have caused remote code execution in situations involving supplemental prompting by a Kerb