[SECURITY] [DLA 661-1] libarchive security update

2016-10-17 Thread Jonas Meurer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libarchive Version: 3.0.4-3+wheezy5 CVE ID : CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 Debian Bug : 840934 840935 840936 Agostino Sarubbo of Gentoo discovered several security vulnerabilities in libarchive, a

[SECURITY] [DLA 660-1] libxrandr security update

2016-10-17 Thread Hugo Lefeuvre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxrandr Version: 2:1.3.2-2+deb7u2 CVE ID : CVE-2016-7947 CVE-2016-7948 Debian Bug : 840441 Insufficient validation of data from the X server in libxrandr before v1.5.0 can cause out of boundary memory writes