[SECURITY] [DLA 231-1] dulwich security update

2015-05-27 Thread Guido Günther
Package: dulwich Version: 0.6.1-1+deb6u1 CVE ID : CVE-2015-0838 Ivan Fratric of the Google Security Team has found a buffer overflow in the C implementation of the apply_delta() function, used when accessing Git objects in pack files. An attacker could take advantage of thi

[SECURITY] [DLA 237-1] mercurial security update

2015-06-04 Thread Guido Günther
Package: mercurial Version: 1.6.4-1+deb6u1 CVE ID : CVE-2014-9390 CVE-2014-9462 CVE-2014-9462 Jesse Hertz of Matasano Security discovered that Mercurial, a distributed version control system, is prone to a command injection vulnerability via a crafted repositor

[SECURITY] [DLA 253-1] libwmf security update

2015-06-26 Thread Guido Günther
Package: libwmf Version: 0.2.8.4-6.2+deb6u1 CVE ID : CVE-2015-0848 CVE-2015-4588 Debian Bug : #787644 The following vulnerabilities were discovered in the Windows Metafile conversion library when reading BMP images embedded into WMF files: CVE-2015-0848 A heap ove

[SECURITY] [DLA 254-1] librack-ruby security update

2015-06-26 Thread Guido Günther
Package: librack-ruby Version: 1.1.0-4+squeeze3 CVE ID : CVE-2015-3225 There is a potential denial of service vulnerability in Rack, a modular Ruby webserver interface. Carefully crafted requests can cause a `SystemStackError` and cause a denial of service attack by exploi

[SECURITY] [DLA 282-1] lighttpd security update

2015-07-25 Thread Guido Günther
Package: lighttpd Version: 1.4.28-2+squeeze1.7 CVE ID : CVE-2014-3566 Debian Bug : #765702 This update allows to disable SSLv3 in lighttpd in order to protect against the POODLE attack. SSLv3 is now disabled by default and can be reenabled (if needed) using the ssl.use-

[SECURITY] [DLA 294-1] wordpress security update

2015-08-19 Thread Guido Günther
Package: wordpress Version: 3.6.1+dfsg-1~deb6u7 CVE ID : CVE-2015-2213 CVE-2015-5622 CVE-2015-5731 CVE-2015-5732 CVE-2015-5734 Several vulnerabilities have been fixed in Wordpress, the popular blogging engine. CVE-2015-2213 SQL Injection allowed a re

[SECURITY] [DLA 265-2] pykerberos regression update

2015-08-26 Thread Guido Günther
Package: pykerberos Version: 1.1+svn4895-1+deb6u2 CVE ID : CVE-2015-3206 It was discovered that the original fix did not disable KDC verification support by default and changed checkPassowrd()'s signature. This update corrects this. This was the text of the original advisi

[SECURITY] [DLA 315-1] nss security update

2015-09-27 Thread Guido Günther
Package: nss Version: 3.12.8-1+squeeze12 CVE ID : CVE-2015-2721 CVE-2015-2730 Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-272

[SECURITY] [DLA 316-1] eglibc security update

2015-09-27 Thread Guido Günther
Package: eglibc Version: 2.11.3-4+deb6u7 CVE ID : CVE-2014-8121 Bug-Reference : 779587 Several vulnerabilities have been discovered in eglibc that may lead to a privilege escalation or denial of service. Glibc pointer guarding weakness A weakness in the dynamic loader

[SECURITY] [DLA 340-1] krb5 security update

2015-11-07 Thread Guido Günther
Package: krb5 Version: 1.8.3+dfsg-4squeeze10 CVE ID : CVE-2015-2695 CVE-2015-2697 Several vulnerabilities were discovered in krb5, the MIT implementation of Kerberos. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-2695

[SECURITY] [DLA 354-1] nss security update

2015-11-29 Thread Guido Günther
Package: nss Version: 3.12.8-1+squeeze13 CVE ID : CVE-2015-7181 CVE-2015-7182 Debian Bug : Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library. The Common Vulnerabilities and Exposures project identifies the following probl

[SECURITY] [DLA 389-1] giflib security update

2016-01-15 Thread Guido Günther
Package: giflib Version: 4.1.6-9+deb6u1 CVE ID : CVE-2015-7555 Debian Bug : 808704 It was discovered that a maliciously crafted GIF can crash the giffix utility which is part of giflib-tools. We recommend that you upgrade your giflib-tools package to version 4.1.6-9+de

[SECURITY] [DLA 427-1] nss security update

2016-02-23 Thread Guido Günther
Package: nss Version: 3.12.8-1+squeeze14 CVE ID : CVE-2016-1938 The s_mp_div function in Mozilla Network Security Services (NSS) before 3.21, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leverag

[SECURITY] [DLA 472-2] icedove regression update

2016-05-18 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: icedove Version: 31.8.0-1~deb7u1.1 CVE ID : CVE-2016-1979 CVE-2016-2805 CVE-2016-2807 Debian Bug : #823430 The security update for icedove did not build on armhf. This is resolved by this upload. The text of the

[SECURITY] [DLA 492-1] pdns security update

2016-05-29 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: pdns Version: 3.1-4.1+deb7u1 CVE ID : CVE-2014-7210 It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected. For Deb

[SECURITY] [DLA 498-1] ruby-activemodel-3.2 security update

2016-05-31 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: ruby-activemodel-3.2 Version: 3.2_3.2.6-3+deb7u1 CVE ID : CVE-2016-0753 Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level write

[SECURITY] [DLA 518-1] mozilla-devscripts security update

2016-06-17 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: mozilla-devscripts Version: 0.32+deb7u1 Debian Bug : 825508 In preparation of the upcoming switch to Icedove 45 the mozilla-devscripts package was updated to generate correct dependencies for rebuilt extensions. For Deb

[SECURITY] [DLA 521-1] firefox-esr security update

2016-06-19 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: firefox-esr Version: 45.2.0esr-1~deb7u1 CVE ID : CVE-2016-2818 CVE-2016-2819 CVE-2016-2821 CVE-2016-2822 CVE-2016-2828 CVE-2016-2831 Multiple security issues have been found in the Mozilla Firefox w

[SECURITY] [DLA 519-1] icedove security update

2016-06-21 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: icedove Version: 45.1.0-1~deb7u1 CVE ID : CVE-2016-2806 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the exec

[SECURITY] [DLA 523-1] enigmail security update

2016-06-23 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: enigmail Version: 1.8.2-4~deb7u2 This uploads corrects the dependencies of the enigmail extension so it becomes installable again together with Icedove 45. For Debian 7 "Wheezy", these problems have been fixed in version 1.

[SECURITY] [DLA 539-1] qemu-kvm security update

2016-07-01 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u13 CVE ID : CVE-2016-3710 CVE-2016-3712 Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 guests. CVE-20

[SECURITY] [DLA 540-1] qemu security update

2016-07-01 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: qemu Version: 1.1.2+dfsg-6a+deb7u13 CVE ID : CVE-2016-3710 CVE-2016-3712 Debian Bug : 823830 Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2016-3710 Wei Xiao and Qinghao Ta

[SECURITY] [DLA 571-1] xen security update

2016-07-30 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: xen Version: 4.1.6.lts1-1 CVE ID : CVE-2014-3672 CVE-2016-3158 CVE-2016-3159 CVE-2016-3710 CVE-2016-3712 CVE-2016-3960 CVE-2016-4480 CVE-2016-6258 Debian Bug : Multiple vulnerabilities have bee

[SECURITY] [DLA 573-1] qemu security update

2016-07-30 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: qemu Version: 1.1.2+dfsg-6+deb7u14 CVE ID : CVE-2015-5239 CVE-2016-2857 CVE-2016-4020 CVE-2016-4439 CVE-2016-5403 CVE-2016-6351 Multiple vulnerabilities have been discovered in QEMU, a fast processo

[SECURITY] [DLA 574-1] qemu-kvm security update

2016-07-30 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u14 CVE ID : CVE-2015-5239 CVE-2016-2857 CVE-2016-4020 CVE-2016-4439 CVE-2016-5403 CVE-2016-6351 Multiple vulnerabilities have been discovered in qemu-kvm, a full

[SECURITY] [DLA 572-1] icedove security update

2016-07-30 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: icedove Version: 1:45.2.0-2~deb7u1 CVE ID : CVE-2016-2818 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the ex

[SECURITY] [DLA 603-1] ruby-activesupport-3.2 security update

2016-08-27 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: ruby-activesupport-3.2 Version: 3.2.6-6+deb7u2 CVE ID : CVE-2015-3227 The support and utility classes used by the Rails 3.2 framework allow remote attackers to cause a denial of service (SystemStackError) via a large

[SECURITY] [DLA 604-1] ruby-actionpack-3.2 security update

2016-08-28 Thread Guido Günther
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: ruby-actionpack-3.2 Version: 3.2.6-6+deb7u3 CVE ID : CVE-2015-7576 CVE-2016-0751 CVE-2016-0752 CVE-2016-2097 CVE-2016-2098 CVE-2016-6316 Multiple vulnerabilities have been discovered in ruby-actionp

[SECURITY] [DLA 640-1] icedove security update

2016-09-30 Thread Guido Günther
Package: icedove Version: 1:45.3.0-1~deb7u1 CVE ID : CVE-2016-2836 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service.

[SECURITY] [DLA 641-1] ruby-activesupport-3.2 security update

2016-09-30 Thread Guido Günther
Package: ruby-activesupport-3.2 Version: 3.2_3.2.6-6+deb7u3 CVE ID : CVE-2016-0753 Active Support in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote a

[SECURITY] [DLA 642-1] ruby-activerecord-3.2 security update

2016-09-30 Thread Guido Günther
Package: ruby-activerecord-3.2 Version: 3.2.6-5+deb7u3 CVE ID : CVE-2016-0753 Active Record in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attacke

[SECURITY] [DLA 658-1] icedove security update

2016-10-16 Thread Guido Günther
Package: icedove Version: 45.4.0-1~deb7u1 CVE ID : CVE-2016-5278, CVE-2016-5270, CVE-2016-5272, CVE-2016-5276, CVE-2016-5277, CVE-2016-5280, CVE-2016-5281, CVE-2016-5284, CVE-2016-5250, CVE-2016-5261, CVE-2016-5257 Multiple security issues have been found in Icedove, Debi

[SECURITY] [DLA 689-1] qemu-kvm security update

2016-10-30 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u18 CVE ID : CVE-2016-7909 CVE-2016-8909 CVE-2016-8910 Debian Bug : 839834 841950 841955 842455 842463 Multiple vulnerabilities have been discovered in qemu-kvm, a full virtualization solution on x86 hardware based on Quick Em

[SECURITY] [DLA 698-1] qemu security update

2016-11-03 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u18 CVE ID : CVE-2016-7909 CVE-2016-8909 CVE-2016-8910 CVE-2016-9101 CVE-2016-9102 CVE-2016-9103 CVE-2016-9104 CVE-2016-9105 CVE-2016-9106 Debian Bug : 839834 841950 841955 842455 842463 Several vulnerabilities were discovered in

[SECURITY] [DLA 699-1] xen security update

2016-11-03 Thread Guido Günther
Package: xen Version: 4.1.6.lts1-3 CVE ID : CVE-2016- Xen does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruc

[SECURITY] [DLA 752-1] icedove security update

2016-12-17 Thread Guido Günther
Package: icedove Version: 45.5.1-1~deb7u1 CVE ID : CVE-2016-5290 CVE-2016-5291 CVE-2016-5296 CVE-2016-5297 CVE-2016-9066 CVE-2016-9074 CVE-2016-9079 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail clien

[SECURITY] [DLA 776-1] samba security update

2017-01-02 Thread Guido Günther
Package: samba Version: 2:3.6.6-6+deb7u11 CVE ID : CVE-2016-2125 Simo Sorce of Red Hat discovered that the Samba client code always requests a forwardable ticket when using Kerberos authentication. A target server, which must be in the current or trusted domain/realm, is gi

[SECURITY] [DLA 783-1] xen security update

2017-01-13 Thread Guido Günther
Package: xen Version: 4.1.6.lts1-5 CVE ID : CVE-2016-10013 CVE-2016-10024 Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-10013 (xsa-204) Xen mishandles SYS

[SECURITY] [DLA 782-1] icedove security update

2017-01-13 Thread Guido Günther
Package: icedove Version: 45.6.0-2 CVE ID : CVE-2016-9893 CVE-2016-9895 CVE-2016-9897 CVE-2016-9898 CVE-2016-9899 CVE-2016-9900 CVE-2016-9904 CVE-2016-9905 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mai

[SECURITY] [DLA 807-1] imagemagick security update

2017-01-30 Thread Guido Günther
Package: imagemagick Version: 8:6.7.7.10-5+deb7u11 CVE ID : CVE-2016-10144 CVE-2016-10145 CVE-2016-10146 CVE-2017-5506 CVE-2017-5507 CVE-2017-5508 CVE-2017-5510 CVE-2017-5511 Debian Bug : #851485, #851483, #851380, #851383, #851382, #851381, #85

[SECURITY] [DLA 842-1] qemu-kvm security update

2017-02-28 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u20 CVE ID : CVE-2017-2615 CVE-2017-2620 CVE-2017-5898 CVE-2017-5973 Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 guests. CVE-2017-2615 The Cir

[SECURITY] [DLA 845-1] qemu security update

2017-03-01 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u20 CVE ID : CVE-2017-2615 CVE-2017-2620 CVE-2017-5898 CVE-2017-5973 Debian Bug : Several vulnerabilities were discovered in qemu, a fast processor emulator. The Common Vulnerabilities and Exposures project identifies the followi

[SECURITY] [DLA 881-1] ejabberd security update

2017-04-01 Thread Guido Günther
Package: ejabberd Version: 2.1.10-4+deb7u2 CVE ID : CVE-2014-8760 Debian Bug : 767521 767535 It was found that ejabberd does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption. For Debian

[SECURITY] [DLA 895-1] openoffice.org-dictionaries update

2017-04-14 Thread Guido Günther
Package: openoffice.org-dictionaries Version: 3.3.0~rc10-4+deb7u1 Debian Bug : #646693 The dictionaries provided by this package had an unversioned conflict against the thunderbird package (which so far was not part of wheezy). Since the next update of Icedove introduces a thu

[SECURITY] [DLA 896-1] icedove/thunderbird security update

2017-04-18 Thread Guido Günther
Package: icedove Version: 1:45.8.0-3~deb7u1 CVE ID : CVE-2017-5373 CVE-2017-5375 CVE-2017-5376 CVE-2017-5378 CVE-2017-5380 CVE-2017-5383 CVE-2017-5390 CVE-2017-5396 CVE-2017-5398 CVE-2017-5400 CVE-2017-5401 CVE-2017-5402

[SECURITY] [DLA 903-1] hunspell-en-us update

2017-04-20 Thread Guido Günther
Package: hunspell-en-us Version: 20070829-6+deb7u1 The dictionary provided by this package had an unnecessary unversioned conflict against the thunderbird package which recently got reintroduced into Wheezy. For Debian 7 "Wheezy", this problem has been fixed in version 20070829-6+

[SECURITY] [DLA 904-1] uzbek-wordlist update

2017-04-20 Thread Guido Günther
Package: uzbek-wordlist Version: 0.6-3.2+deb7u1 The dictionary provided by this package had an unnecessary unversioned conflict against the thunderbird package which recently got reintroduced into Wheezy. For Debian 7 "Wheezy", this problem has been fixed in version 0.6-3.2+deb7u1

[SECURITY] [DLA 939-1] qemu-kvm security update

2017-05-11 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u21 CVE ID : CVE-2016-9603 CVE-2017-7718 CVE-2017-7980 Multiple vulnerabilities have been discovered in qemu-kvm, a full virtualization solution on x86 hardware based on Quick Emulator(Qemu). The Common Vulnerabilities and Exposur

[SECURITY] [DLA 965-1] qemu-kvm security update

2017-05-30 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u22 CVE ID : CVE-2016-9602 CVE-2017-7377 CVE-2017-7471 CVE-2017-7493 CVE-2017-8086 Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 gues

[SECURITY] [DLA 979-1] debian-security-support update

2017-06-07 Thread Guido Günther
Package: debian-security-support Version: 2017.06.02+deb7u1 Besides bringing the package up to date regarding translations this update marks several packages as no longer supported by wheezy-lts: autotrace, inspircd, ioquake3, kfreebsd-8, kfreebsd-9, matrixssl, teeworlds and trn

[SECURITY] [DLA 1007-1] icedove/thunderbird security update

2017-07-02 Thread Guido Günther
Package: icedove Version: 1:52.2.1-1~deb7u1 CVE ID : CVE-2017-5470 CVE-2017-5472 CVE-2017-7749 CVE-2017-7750 CVE-2017-7751 CVE-2017-7752 CVE-2017-7754 CVE-2017-7756 CVE-2017-7757 CVE-2017-7758 CVE-2017-7764 CVE-2017-7771

[SECURITY] [DLA 1027-1] heimdal security update

2017-07-14 Thread Guido Günther
Package: heimdal Version: 1.6~git20120403+dfsg1-2+deb7u1 CVE ID : CVE-2017-11103 Debian Bug : 868208 Jeffrey Altman, Viktor Duchovni and Nico Williams identified a mutual authentication bypass vulnerability in Heimdal Kerberos. Also known as Orpheus' Lyre, this vulnerab

[SECURITY] [DLA 1035-1] qemu security update

2017-07-21 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u22 CVE ID : CVE-2016-9602 CVE-2016-9603 CVE-2017-7377 CVE-2017-7471 CVE-2017-7493 CVE-2017-7718 CVE-2017-7980 CVE-2017-8086 Several vulnerabilities were discovered in qemu, a fast processor emulator. The Common Vuln

[SECURITY] [DLA 1071-1] qemu-kvm security update

2017-08-28 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u23 CVE ID : CVE-2017-6505 CVE-2017-8309 CVE-2017-10664 CVE-2017-11434 Multiple vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 guests based on the Quick Emulato

[SECURITY] [DLA 1070-1] qemu security update

2017-08-28 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u23 CVE ID : CVE-2017-6505 CVE-2017-8309 CVE-2017-10664 CVE-2017-11434 Multiple vulnerabilities were discovered in qemu, a fast processor emulator. The Common Vulnerabilities and Exposures project identifies the following problems: C

[SECURITY] [DLA 1080-1] gnupg security update

2017-08-31 Thread Guido Günther
Package: gnupg Version: 1.4.12-7+deb7u9 CVE ID : CVE-2017-7526 Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom discovered that gnupg is prone to a local side-channel attack a

[SECURITY] [DLA 1086-1] enigmail security update

2017-09-03 Thread Guido Günther
Package: enigmail Version: 2:1.9.8.1-1~deb7u1 In DLA 1007-1 Thunderbird was upgraded to the latest ESR series. This update upgrades Enigmail, the OpenPGP extention for Thunderbird, to version 1.9.8.1 to restore full compatibility. For Debian 7 "Wheezy", these problems have been fi

[SECURITY] [DLA 1087-1] icedove/thunderbird security update

2017-09-05 Thread Guido Günther
Package: icedove Version: 1:52.3.0-4~deb7u1 CVE ID : CVE-2017-7753 CVE-2017-7779 CVE-2017-7784 CVE-2017-7785 CVE-2017-7786 CVE-2017-7787 CVE-2017-7791 CVE-2017-7792 CVE-2017-7800 CVE-2017-7801 CVE-2017-7802 CVE-2017-7803 CVE

[SECURITY] [DLA 1090-1] tcpdump security update

2017-09-05 Thread Guido Günther
Package: tcpdump Version: 4.9.0-1~deb7u2 CVE ID : CVE-2017-11108 CVE-2017-11541 CVE-2017-11542 CVE-2017-11543 Several vulnerabilities have been discovered in tcpdump, a command-line network traffic analyzer. These vulnerabilities might result in denial of service (applicati

[SECURITY] [DLA 1087-2] icedove/thunderbird regression update

2017-09-07 Thread Guido Günther
Package: icedove Version: 1:52.3.0-4~deb7u2 The update for icedove/thunderbird issued as DLA-1087-1 did not build on i386. This update corrects this. For reference, the original advisory text follows. Multiple security issues have been found in the Mozilla Thunderbird mail client

[SECURITY] [DLA 1097-1] tcpdump security update

2017-09-15 Thread Guido Günther
Package: tcpdump Version: 4.9.2-1~deb7u1 CVE ID : CVE-2017-12894 CVE-2017-12895 CVE-2017-12896 CVE-2017-12897 CVE-2017-12898 CVE-2017-12899 CVE-2017-12900 CVE-2017-12901 CVE-2017-12902 CVE-2017-12985 CVE-2017-12986 CVE-2017-12987

[SECURITY] [DLA 1110-1] samba security update

2017-09-25 Thread Guido Günther
Package: samba Version: 2:3.6.6-6+deb7u14 CVE ID : CVE-2017-12150 CVE-2017-12163 CVE-2017-12150 Stefan Metzmacher discovered multiple code paths where SMB signing was not enforced. CVE-2017-12163 Yihan Lian and Zhibin Hu discovered that insufficient range che

[SECURITY] [DLA 1115-1] debsecan update

2017-09-27 Thread Guido Günther
Package: debsecan Version: 0.4.16+nmu1+deb7u1 Debian Bug : 842428 Debsecan in Wheezy in its default configuration currently fails to download recent vulnerability data due to an URL change. For Debian 7 "Wheezy", these problems have been fixed in version 0.4.16+nmu1+deb7u1. W

[SECURITY] [DLA 1128-1] qemu-kvm security update

2017-10-08 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u24 CVE ID : CVE-2017-14167 CVE-2017-15038 Multiple vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 guests based on the Quick Emulator(Qemu). CVE-2017-14167

[SECURITY] [DLA 1129-1] qemu security update

2017-10-08 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u24 CVE ID : CVE-2017-14167 CVE-2017-15038 Multiple vulnerabilities were discovered in qemu, a fast processor emulator. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-14167 Incorrec

[SECURITY] [DLA 1153-1] icedove/thunderbird security update

2017-11-01 Thread Guido Günther
Package: thunderbird Version: 1:52.4.0-1~deb7u1 CVE ID : CVE-2017-7793 CVE-2017-7805 CVE-2017-7810 CVE-2017-7814 CVE-2017-7818 CVE-2017-7819 CVE-2017-7823 CVE-2017-7824 CVE-2017-7825 Multiple security issues have been found in the Mozilla

[SECURITY] [DLA 1199-1] thunderbird security update

2017-12-09 Thread Guido Günther
Package: thunderbird Version: 1:52.5.0-1~deb7u1 CVE ID : CVE-2017-7826 CVE-2017-7828 CVE-2017-7830 Multiple security issues have been found in the Mozilla Thunderbird mail client: Multiple memory safety errors, use after free and other implementation errors may lead to cras

[SECURITY] [DLA 1222-1] ruby1.8 security update

2017-12-25 Thread Guido Günther
Package: ruby1.8 Version: 1.8.7.358-7.1+deb7u5 CVE ID : CVE-2017-17405 CVE-2017-17790 Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-17405

[SECURITY] [DLA 1221-1] ruby1.9.1 security update

2017-12-25 Thread Guido Günther
Package: ruby1.9.1 Version: 1.9.3.194-8.1+deb7u7 CVE ID : CVE-2017-17405 CVE-2017-17790 Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-17405

[SECURITY] [DLA 1223-1] thunderbird security update

2017-12-27 Thread Guido Günther
Package: thunderbird Version: 1:52.5.2-1~deb7u1 CVE ID : CVE-2017-7829 CVE-2017-7846 CVE-2017-7847 CVE-2017-7848 Multiple security issues have been found in the Mozilla Thunderbird mail client including information leaks, unintended JavaScript execution and sender address s

[SECURITY] [DLA 1262-1] thunderbird security update

2018-01-29 Thread Guido Günther
Package: thunderbird Version: 1:52.6.0-1~deb7u1 CVE ID : CVE-2018-5089 CVE-2018-5095 CVE-2018-5096 CVE-2018-5097 CVE-2018-5098 CVE-2018-5099 CVE-2018-5102 CVE-2018-5103 CVE-2018-5104 CVE-2018-5117 Debian Bug : 885157 885158 887766 Mul

[SECURITY] [DLA 1263-1] debian-security-support update

2018-01-29 Thread Guido Günther
Package: debian-security-support Version: 2018.01.29~deb7u1 This update marks several packages as no longer supported by wheezy-lts: teamspeak-server, teamspeak-client, libstruts1.2-java, nvidia-graphics-drivers, glassfish, jbossas4, libnet-ping-external-perl, mp3gain, tor, jasper