[SECURITY] [DLA 1485-1] bind9 security update

2018-08-30 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bind9 Version: 1:9.9.5.dfsg-9+deb8u16 CVE ID : CVE-2018-5740 CVE-2018-5740 The "deny-answer-aliases" feature in BIND has a flaw which can cause named to exit with an assertion failure. For Debian 8

[SECURITY] [DLA 1483-1] 389-ds-base security update

2018-08-30 Thread Mike Gabriel
Package: 389-ds-base Version: 1.3.3.5-4+deb8u2 CVE ID : CVE-2018-10871 CVE-2018-10935 Debian Bug : 906985 CVE-2018-10871 By default nsslapd-unhashed-pw-switch was set to 'on'. So a copy of the unhashed password was kept in modifiers and was possibly logged in

[SECURITY] [DLA 1484-1] squirrelmail security update

2018-08-30 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: squirrelmail Version: 2:1.4.23~svn20120406-2+deb8u3 CVE IDs: CVE-2018-14950 CVE-2018-14951 CVE-2018-14952 CVE-2018-14953 CVE-2018-14954 CVE-2018-14955 Debian Bug : #905023 It was discovered