[SECURITY] [DLA 1967-1] libpcap security update

2019-10-21 Thread Abhijith PA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libpcap Version: 1.6.2-2+deb8u1 CVE ID : CVE-2019-15165 Debian Bug : 941697 libpcap (Packet CAPture), a low-level network monitoring library, does not properly validate the PHB header length before allocating

[SECURITY] [DLA 1962-1] graphite-web security update

2019-10-21 Thread Utkarsh Gupta
Package: graphite-web Version: 0.9.12+debian-6+deb8u1 CVE ID : CVE-2017-18638 The 'send_email' function in graphite-web/webapp/graphite/composer/views.py in Graphite is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web

[SECURITY] [DLA 1961-1] milkytracker security update

2019-10-21 Thread Utkarsh Gupta
Package: milkytracker Version: 0.90.85+dfsg-2.2+deb8u1 CVE ID : CVE-2019-14464 CVE-2019-14496 CVE-2019-14497 Debian Bug : 933964 Fredric discovered a couple of buffer overflows in MilkyTracker, of which, a brief description is given below. CVE-2019-14464

[SECURITY] [DLA 1968-1] imagemagick security update

2019-10-21 Thread Hugo Lefeuvre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: imagemagick Version: 8:6.8.9.9-5+deb8u18 CVE ID : CVE-2019-11470 CVE-2019-14981 CVE-2019-15139 CVE-2019-15140 Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-11470