[SECURITY] [DLA 1665-1] netmask security update

2019-02-06 Thread Antoine Beaupré
Package: netmask Version: 2.3.12+deb8u1 Debian Bug : 921565 A buffer overflow was found in netmask which would crash when called with arbitrarily long inputs. For Debian 8 "Jessie", this problem has been fixed in version 2.3.12+deb8u1. We recommend that you upgrade your

[SECURITY] [DLA 1664-1] golang security update

2019-02-06 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: golang Version: 2:1.3.3-1+deb8u1 CVE ID : CVE-2019-6486 Debian Bug : #920548 It was discovered that there was a denial of service vulnerability or possibly even the ability to conduct private key recovery

[SECURITY] [DLA 1660-1] rssh security update

2019-02-06 Thread Antoine Beaupré
Package: rssh Version: 2.3.4-4+deb8u2 CVE ID : CVE-2019-3463 CVE-2019-3464 More vulnerabilities were found by Nick Cleaton in the rssh code that could lead to arbitrary code execution under certain circumstances. CVE-2019-3463 reject rsync --daemon and --config

[SECURITY] [DLA 1661-1] mumble security update

2019-02-06 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: mumble Version: 1.2.8-2+deb8u1 CVE ID : CVE-2018-20743 Debian Bug : 919249 It has been found that the mumble-server mishandles multiple concurrent requests that are persisted in the database, which allows

[SECURITY] [DLA 1654-1] libav security update

2019-02-06 Thread Mike Gabriel
Package: libav Version: 6:11.12-1~deb8u5 CVE ID : CVE-2014-8542 CVE-2015-1207 CVE-2017-7863 CVE-2017-7865 CVE-2017-14169 CVE-2017-14223 Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library.