[SECURITY] [DLA 1487-1] libtirpc security update

2018-08-31 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libtirpc Version: 0.2.5-1+deb8u2 CVE ID : CVE-2018-14622 CVE-2018-14622 Fix for egmentation fault due to pointer becoming NULL. For Debian 8 "Jessie", this problem has been fixed in version 0.2.5-1+deb8u2.

[SECURITY] [DLA 1488-1] spice security update

2018-08-31 Thread Mike Gabriel
Package: spice Version: 0.12.5-1+deb8u6 CVE ID : CVE-2018-10873 Debian Bug : #906315 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server,

[SECURITY] [DLA 1486-1] spice security update

2018-08-31 Thread Mike Gabriel
Package: spice Version: 0.12.5-1+deb8u6 CVE ID : CVE-2018-10873 Debian Bug : #906315 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server,

[SECURITY] [DLA 1488-1] mariadb-10.0 security update

2018-08-31 Thread Holger Levsen
Package: mariadb-10.0 Version: 10.0.36-0+deb8u1 CVE ID : CVE-2018-3058 CVE-2018-3063 CVE-2018-3064 CVE-2018-3066 Debian Bug : 904121 Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new

[SECURITY] [DLA 1489-1] spice-gtk security update

2018-08-31 Thread Mike Gabriel
Package: spice-gtk Version: 0.25-1+deb8u1 CVE ID : CVE-2018-10873 Debian Bug : 906316 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server,