[SECURITY] [DLA 317-1] vorbis-tools security update

2015-09-29 Thread Mike Gabriel
Package: vorbis-tools Version: 1.4.0-1+deb6u1 CVE ID : CVE-2014-9638 CVE-2014-9639 CVE-2014-9640 CVE-2015-6749 Debian Bug : #771363 #797461 #776086 Various issues have been fixed in Debian LTS (squeeze) for package vorbis-tools. CVE-2014-9638 A crafted WAV file wi

[SECURITY] [DLA 313-1] virtualbox-ose security update

2015-09-29 Thread Mike Gabriel
Package: virtualbox-ose Version: 3.2.28-dfsg-1+squeeze1 CVE ID : CVE-2013-3792 CVE-2014-2486 CVE-2014-2488 CVE-2014-2489 CVE-2015-2594 Bugs : #715327 #754939 #792446 The latest maintenance release of the VirtualBox (OSE) 3.2.x series (i.e., versi

[SECURITY] [DLA 318-1] flightgear security update

2015-09-29 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: flightgear Version: 1.9.1-1.1 Debian Bug : 780712 It was discovered that flightgear, a Flight Gear Flight Simulator game, did not perform adequate filesystem validation checks in its fgValidatePath routine. Regards, -

[SECURITY] [DLA 288-2] openssh regression update

2015-09-29 Thread Mike Gabriel
Package: openssh Version: 1:5.5p1-6+squeeze7 CVE ID : CVE-2015-5600 In Debian LTS (squeeze), the fix for CVE-2015-5600[1] in openssh 1:5.5p1-6+squeeze7 breaks authentication mechanisms that rely on the keyboard-interactive method. Thanks to Colin Watson for making aware of

[SECURITY] [DLA 320-1] libemail-address-perl security update

2015-09-29 Thread Mike Gabriel
Package: libemail-address-perl Version: 1.889-2+deb6u2 Pali Rohár discovered [1] a possible DoS attack in any software which uses the Email::Address Perl module for parsing string input to a list of email addresses. By default Email::Address module, version v1.907 (and all before