[SECURITY] [DLA 403-1] radicale security update

2016-01-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: radicale Version: 0.3-2+deb6u1 CVE ID : CVE-2015-8747 CVE-2015-8748 Debian Bug : 809920 Several issues have been discovered by Unrud in Radicale, a calendar and addressbook server. A remote attacker could exploit

[SECURITY] [DLA 410-1] openjdk-6 security update

2016-02-04 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: openjdk-6 Version: 6b38-1.13.10-1~deb6u1 CVE ID : CVE-2015-7575 CVE-2015-8126 CVE-2015-8472 CVE-2016-0402 CVE-2016-0448 CVE-2016-0466 CVE-2016-0483 CVE-2016-0494 Several vulnerabili

[SECURITY] [DLA 418-1] wordpress security update

2016-02-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wordpress Version: 3.6.1+dfsg-1~deb6u9 CVE ID : CVE-2016-2221 CVE-2016- Debian Bug : 813697 WordPress versions 4.4.1 and earlier are affected by two security issues: a possible Side Request Forgery Vulnerabil

[SECURITY] [DLA 422-1] python-imaging security update

2016-02-21 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: python-imaging Version: 1.1.7-2+deb6u2 CVE ID : CVE-2016-0775 Debian Bug : 813909 Two buffer overflows were discovered in python-imaging, a Python library for loading and manipulating image files, which may lead

[SECURITY] [DLA 435-1] tomcat6 security update

2016-02-27 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat6 Version: 6.0.45-1~deb6u1 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 Tomcat 6, an implementation of the Java Servlet and the JavaServer Pages

[SECURITY] [DLA 441-1] pcre3 security update

2016-02-29 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: pcre3 Version: 8.02-1.1+deb6u1 Debian Bug : 815921 HP's Zero Day Initiative has identified a vulnerability affecting the pcre3 package. It was assigned ZDI id ZDI-CAN-3542. A CVE identifier has not been assigned yet. PC

[SECURITY] [DLA 443-1] bsh security update

2016-02-29 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bsh Version: 2.0b4-12+deb6u1 CVE ID : CVE-2016-2510 A remote code execution vulnerability was found in BeanShell, an embeddable Java source interpreter with object scripting language features. CVE-2016-2510:

[SECURITY] Debian 6 Squeeze has reached end-of-life

2016-03-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 The Debian Long Term Support (LTS) Team hereby announces that Debian 6 ("Squeeze") support has reached its end-of-life on February 29, 2016, five years after its initial release on February 6, 2011. There will be no further security support for Debi

[SECURITY] Security support for Wheezy handed over to the LTS team

2016-04-25 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 As of 25 April, one year after the release of Debian 8, alias "Jessie", and nearly three years after the release of Debian 7, alias "Wheezy", regular security support for Wheezy comes to an end. The Debian Long Term Support (LTS) Team will take over

[SECURITY] [DLA 449-1] botan1.10 security update

2016-04-30 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: botan1.10 Version: 1.10.5-1+deb7u1 CVE ID : CVE-2014-9742 CVE-2015-5726 CVE-2015-5727 CVE-2015-7827 CVE-2016-2194 CVE-2016-2195 CVE-2016-2849 Several security vulnerabilities were fo

[SECURITY] [DLA 450-1] gdk-pixbuf security update

2016-04-30 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: gdk-pixbuf Version: 2.26.1-1+deb7u4 CVE ID : CVE-2015-7552 CVE-2015-7674 A heap-based buffer overflow has been discovered in gdk-pixbuf, a library for image loading and saving facilities, fast scaling and compositing

[SECURITY] [DLA 451-1] openjdk-7 security update

2016-05-03 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: openjdk-7 Version: 7u101-2.6.6-2~deb7u1 CVE ID : CVE-2016-0636 CVE-2016-0686 CVE-2016-0687 CVE-2016-0695 CVE-2016-3425 CVE-2016-3426 CVE-2016-3427 Several vulnerabilities have been discovered in Open

[SECURITY] [DLA 452-1] smarty3 security update

2016-05-03 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: smarty3 Version: 3.1.10-2+deb7u1 CVE ID : CVE-2014-8350 Debian Bug : 765920 Smarty3, a template engine for PHP, allowed remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as de

[SECURITY] default-java switch to OpenJDK 7 and java-common update

2016-05-04 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: java-common Version: 0.47+deb7u1 In preparation for the upcoming default-java switch to OpenJDK 7 on 26 June 2016, the java-common package was updated to inform users about the intended change. The news will be automaticall

[SECURITY] [DLA 460-1] file security update

2016-05-07 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: file Version: 5.11-2+deb7u9 CVE ID : CVE-2015-8865 A malformed magic file could trigger a segmentation fault and thus crash applications due to a buffer over-write in the file_check_mem function. For Debian 7 "Whee

[SECURITY] [DLA 461-1] nagios3 security update

2016-05-07 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: nagios3 Version: 3.4.1-3+deb7u2 CVE ID : CVE-2014-1878 A stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios, a monitoring and management system for hosts, services and networks, allowed r

[SECURITY] [DLA 463-1] ikiwiki security update

2016-05-09 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: ikiwiki Version: 3.20120629.2+deb7u1 CVE ID : CVE-2016-4561 Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki's use of

[SECURITY] [DLA 449-2] botan1.10 regression update

2016-05-10 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: botan1.10 Version: 1.10.5-1+deb7u1 Debian Bug : 823297 The security update for botan1.10 caused a regression in monotone due to a ABI change. In order to fix this issue all reverse-dependencies of botan1.10 have been re

[SECURITY] [DLA 468-1] libuser security update

2016-05-12 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libuser Version: 1:0.56.9.dfsg.1-1.2+deb7u1 CVE ID : CVE-2015-3245 CVE-2015-3246 Debian Bug : 793465 Two security vulnerabilities were discovered in libuser, a library that implements a standardized interface for

[SECURITY] [DLA 471-1] jansson security update

2016-05-13 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: jansson Version: 2.3.1-2+deb7u1 CVE ID : CVE-2016-4425 Debian Bug : 823238 Applications that depend on Jansson, a C library for encoding, decoding and manipulating JSON data, could crash due to stack exhaustion

[SECURITY] [DLA 472-1] icedove security update

2016-05-14 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: icedove Version: 38.8.0-1~deb7u1 CVE ID : CVE-2016-1979 CVE-2016-2805 CVE-2016-2807 Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client. Multiple memory safety

[SECURITY] [DLA 473-1] wpa security update

2016-05-14 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wpa Version: 1.0-3+deb7u4 CVE ID : CVE-2016-4476 CVE-2016-4477 Debian Bug : 823411 A vulnerability was found in how hostapd and wpa_supplicant writes the configuration file update for the WPA/WPA2 passphrase para

[SECURITY] [DLA 475-1] python-tornado security update

2016-05-15 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: python-tornado Version: 2.3-2+deb7u1 CVE ID : CVE-2014-9720 It was discovered that python-tornado, a Python web framework and asynchronous networking library, was susceptible for the BREACH attack. The XSRF token is

[SECURITY] [DLA 483-1] expat security update

2016-05-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: expat Version: 2.1.0-1+deb7u3 CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, a XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows d

[SECURITY] [DLA 484-1] graphicsmagick security update

2016-05-21 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Version: 1.3.16-1.1+deb7u1 CVE ID : CVE-2015-8808 CVE-2016-2317 CVE-2016-2318 CVE-2016-3714 CVE-2016-3715 CVE-2016-3716 CVE-2016-3717 CVE-2016-3718 Debian Bug : 814732 Several security vulnerabil

[SECURITY] [DLA 488-1] xymon security update

2016-05-25 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: xymon Version: 4.3.0~beta2.dfsg-9.1+deb7u1 CVE ID : CVE-2016-2054 CVE-2016-2055 CVE-2016-2056 CVE-2016-2058 Markus Krell discovered that Xymon (formerly known as Hobbit), a network- and applications-monitoring syste

[SECURITY] [DLA 490-1] bozohttpd security update

2016-05-25 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bozohttpd Version: 2018-1+deb7u1 CVE ID : CVE-2014-5015 CVE-2015-8212 Debian Bug : 755197 Two security vulnerabilities have been discovered in bozohttpd, a small HTTP server. CVE-2014-5015 Bozotic HTTP

[SECURITY] [DLA 501-1] gdk-pixbuf security update

2016-06-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: gdk-pixbuf Version: 2.26.1-1+deb7u5 CVE ID : CVE-2015-7552 It was discovered that the original fix for CVE-2015-7552 (DLA-450-1) was incomplete. A heap-based buffer overflow in gdk-pixbuf, a library for image loadi

[SECURITY] Debian 7 Wheezy LTS now supporting armel and armhf

2016-06-02 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Debian Long Term Support (LTS) is a project created to extend the life of all Debian stable releases to (at least) 5 years. Thanks to the LTS sponsors, Debian's buildd maintainers and the Debian FTP Team are excited to announce that two new architec

[SECURITY] [DLA 502-1] graphicsmagick security update

2016-06-02 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: graphicsmagick Version: 1.3.16-1.1+deb7u2 CVE ID : CVE-2016-5118 Debian Bug : 825800 Bob Friesenhahn discovered a command injection vulnerability in Graphicsmagick, a program suite for image manipulation. An atta

[SECURITY] [DLA 504-1] libxstream-java security update

2016-06-08 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxstream-java Version: 1.4.2-1+deb7u1 CVE ID : CVE-2016-3674 Debian Bug : 819455 It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity

[SECURITY] [DLA 505-1] libpdfbox-java security update

2016-06-08 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libpdfbox-java Version: 1:1.7.0+dfsg-4+deb7u1 CVE ID : CVE-2016-2175 Apache PDFBox did not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks v

[SECURITY] [DLA 508-1] expat security update

2016-06-08 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: expat Version: 2.1.0-1+deb7u4 CVE ID : CVE-2012-6702 CVE-2016-5300 Two related issues have been discovered in Expat, a C library for parsing XML. CVE-2012-6702 This issue was introduced when CVE-2012-0876 was

[SECURITY] [DLA 511-1] libtorrent-rasterbar security update

2016-06-11 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libtorrent-rasterbar Version: 0.15.10-1+deb7u1 CVE ID : CVE-2016-5301 Debian Bug : 826380 A specially crafted HTTP response from a tracker (or potentially a UPnP broadcast) can crash libtorrent in the parse_chun

[SECURITY] [DLA 526-1] mysql-connector-java security update

2016-06-25 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: mysql-connector-java Version: 5.1.39-1~deb7u1 CVE ID : CVE-2015-2575 A vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J) has been discovered that may result in unauthorized

[SECURITY] [DLA 528-1] libcommons-fileupload-java security update

2016-06-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libcommons-fileupload-java Version: 1.2.2-1+deb7u3 CVE ID : CVE-2016-3092 A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below

[SECURITY] [DLA 529-1] tomcat7 security update

2016-06-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u5 CVE ID : CVE-2016-3092 A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the b

[SECURITY] [DLA 530-1] java-common security update

2016-06-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: java-common Version: 0.47+deb7u2 As previously announced [1][2], the default Java implementation has been switched from OpenJDK 6 to OpenJDK 7. We strongly recommend to remove the unsupported OpenJDK 6 packages which will r

[SECURITY] [DLA 537-1] roundcube security update

2016-06-30 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: roundcube Version: 0.7.2-9+deb7u3 CVE ID : CVE-2015-8864 Roundcube, a webmail solution for IMAP servers, was susceptible to cross-site-scripting (XSS) vulnerabilities when handling SVG images. When right-clicking on

[SECURITY] [DLA 554-1] libarchive security update

2016-07-20 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libarchive Version: 3.0.4-3+wheezy2 CVE ID : CVE-2015-8917 CVE-2015-8919 CVE-2015-8920 CVE-2015-8921 CVE-2015-8922 CVE-2015-8923 CVE-2015-8924 CVE-2015-8925 CVE-2015-8926

[SECURITY] [DLA 555-1] python-django security update

2016-07-21 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: python-django Version: 1.4.5-1+deb7u17 CVE ID : CVE-2016-6186 Debian Bug : 831799 It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in

[SECURITY] [DLA 561-1] uclibc security update

2016-07-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: uclibc Version: 0.9.32-1+deb7u1 CVE ID : CVE-2016-2224 CVE-2016-2225 CVE-2016-6264 Several vulnerabilities have been discovered in uClibc, an implementation of the standard C library that is much smaller than glibc,

[SECURITY] [DLA 562-1] gosa security update

2016-07-26 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: gosa Version: 2.7.4-4.3~deb7u3 CVE ID : CVE-2015-8771 GOsa² is a combination of system-administrator and end-user web interface, designed to handle LDAP based setups. A code injection vulnerability in the Samba plu

[SECURITY] [DLA 568-1] wordpress security update

2016-07-29 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wordpress Version: 3.6.1+dfsg-1~deb7u11 CVE ID : CVE-2016-5387 CVE-2016-5832 CVE-2016-5834 CVE-2016-5835 CVE-2016-5838 CVE-2016-5839 Debian Bug : 828225 Several vulnerabilities were discovered i

[SECURITY] [DLA 576-1] libdbd-mysql-perl security update

2016-07-30 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libdbd-mysql-perl Version: 4.021-1+deb7u1 CVE ID : CVE-2014-9906 CVE-2015-8949 Two use-after-free vulnerabilities were discovered in DBD::mysql, a Perl DBI driver for the MySQL database server. A remote attacker can

[SECURITY] [DLA 585-1] firefox-esr security update

2016-08-04 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: firefox-esr Version: 45.3.0esr-1~deb7u1 CVE ID : CVE-2016-2830 CVE-2016-2836 CVE-2016-2837 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262

[SECURITY] [DLA 586-1] curl security update

2016-08-04 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: curl Version: 7.26.0-1+wheezy14 CVE ID : CVE-2016-5419 CVE-2016-5420 CVE-2016-5419 Bru Rom discovered that libcurl would attempt to resume a TLS session even if the client certificate had changed. CVE-2016-

[SECURITY] [DLA 610-1] tiff3 security update

2016-09-04 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tiff3 Version: 3.9.6-11+deb7u1 CVE ID : CVE-2010-2596 CVE-2013-1961 CVE-2014-8128 CVE-2014-8129 CVE-2014-9655 CVE-2015-1547 CVE-2015-8665 CVE-2015-8683 CVE-2016-3186

[SECURITY] [DLA 622-1] tomcat6 security update

2016-09-15 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat6 Version: 6.0.45+dfsg-1~deb7u2 CVE ID : CVE-2016-1240 Dawid Golunski from legalhackers.com discovered that Debian's version of Tomcat 6 was vulnerable to a local privilege escalation. Local attackers who hav

[SECURITY] [DLA 623-1] tomcat7 security update

2016-09-15 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u6 CVE ID : CVE-2016-1240 Dawid Golunski from legalhackers.com discovered that Debian's version of Tomcat 7 was vulnerable to a local privilege escalation. Local attackers who have gain

[SECURITY] [DLA 629-1] jackrabbit security update

2016-09-18 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: jackrabbit Version: 2.3.6-1+deb7u2 CVE ID : CVE-2016-6801 Debian Bug : 838204 Lukas Reschke discovered that Apache Jackrabbit, a content repository implementation for Java, was vulnerable to Cross-Site-Request-F

[SECURITY] [DLA 630-1] zookeeper security update

2016-09-18 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: zookeeper Version: 3.3.5+dfsg1-2+deb7u1 CVE ID : CVE-2016-5017 Lyon Yang discovered that the C client shells cli_st and cli_mt of Apache Zookeeper, a high-performance coordination service for distributed application

[SECURITY] [DLA 633-1] wordpress security update

2016-09-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wordpress Version: 3.6.1+dfsg-1~deb7u12 CVE ID : CVE-2015-8834 CVE-2016-4029 CVE-2016-5836 CVE-2016-6634 CVE-2016-6635 CVE-2016-7168 CVE-2016-7169 Several vulnerabilities were discov

[SECURITY] [DLA 648-1] c-ares security update

2016-10-06 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: c-ares Version: 1.9.1-3+deb7u1 CVE ID : CVE-2016-5180 Debian Bug : 839151 Gzob Qq discovered that the query-building functions in c-ares, an asynchronous DNS request library would not correctly process crafted q

[SECURITY] [DLA 664-1] libxrender security update

2016-10-18 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxrender Version: 1:0.9.7-1+deb7u3 CVE ID : CVE-2016-7949 CVE-2016-7950 Debian Bug : 840443 Tobias Stoeckmann from the OpenBSD project has discovered a number of issues in the way various X client libraries ha

[SECURITY] [DLA 666-1] guile-2.0 security update

2016-10-18 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: guile-2.0 Version: 2.0.5+1-3+deb7u1 CVE ID : CVE-2016-8605 CVE-2016-8606 Debian Bug : 840555 840556 Several vulnerabilities were discovered in GNU Guile, an implementation of the Scheme programming language. The

[SECURITY] [DLA 667-1] libxv security update

2016-10-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxv Version: 2:1.0.7-1+deb7u2 CVE ID : CVE-2016-5407 Debian Bug : 840438 Tobias Stoeckmann from the OpenBSD project has discovered a number of issues in the way various X client libraries handle the responses

[SECURITY] [DLA 668-1] libass security update

2016-10-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libass Version: 0.10.0-3+deb7u1 CVE ID : CVE-2016-7969 CVE-2016-7972 Several vulnerabilities were discovered in libass, a library for manipulating the SubStation Alpha (SSA) subtitle file format. The Common Vulnerab

[SECURITY] [DLA 673-1] kdepimlibs security update

2016-10-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: kdepimlibs Version: 4:4.8.4-2+deb7u1 CVE ID : CVE-2016-7966 Debian Bug : 840546 Roland Tapken discovered that insufficient input sanitizing in KMail's plain text viewer allowed attackers the injection of HTML co

[SECURITY] [DLA 715-1] drupal7 security update

2016-11-21 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: drupal7 Version: 7.14-2+deb7u15 CVE ID : CVE-2016-9449 CVE-2016-9451 Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advis

[SECURITY] [DLA 717-1] moin security update

2016-11-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: moin Version: 1.9.4-8+deb7u3 CVE ID : CVE-2016-7146 CVE-2016-9119 Debian Bug : 844338 844340 Several cross-site scripting vulnerabilities were discovered in moin, a Python clone of WikiWiki. A remote attacker can

[SECURITY] [DLA 728-1] tomcat6 security update

2016-12-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat6 Version: 6.0.45+dfsg-1~deb7u3 CVE ID : CVE-2016-0762 CVE-2016-5018 CVE-2016-6794 CVE-2016-6796 CVE-2016-6797 CVE-2016-6816 CVE-2016-8735 Debian Bug : 841655 842662 842663

[SECURITY] [DLA 729-1] tomcat7 security update

2016-12-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u7 CVE ID : CVE-2016-0762 CVE-2016-5018 CVE-2016-6794 CVE-2016-6796 CVE-2016-6797 CVE-2016-6816 CVE-2016-8735 Debian Bug : 841655 842662 842663 84266

[SECURITY] [DLA 742-1] chrony security update

2016-12-13 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: chrony Version: 1.24-3.1+deb7u4 CVE ID : CVE-2016-1567 Debian Bug : 812923 568492 It was discovered that Chrony, a versatile implementation of the Network Time Protocol, did not verify peer associations of symmet

[SECURITY] [DLA 745-1] most security update

2016-12-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: most Version: 5.0.0a-2.2 CVE ID : CVE-2016-1253 Debian Bug : 848132 The most pager can automatically open files compressed with gzip, bzip2 and (in Debian) LZMA. Alberto Garcia discovered that Debian's version of

[SECURITY] [DLA 746-1] tomcat6 security update

2016-12-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat6 Version: 6.0.45+dfsg-1~deb7u4 CVE ID : CVE-2016-9774 Debian Bug : 845393 845425 846298 Paul Szabo discovered a potential privilege escalation that could be exploited in the situation envisaged in DLA-622-

[SECURITY] [DLA 747-1] libupnp security update

2016-12-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libupnp Version: 1:1.6.17-1.2+deb7u2 CVE ID : CVE-2016-8863 Debian Bug : 842093 Scott Tenaglia discovered a heap-based buffer overflow in libupnp, a portable SDK for UPnP Devices. That can lead to denial of servi

[SECURITY] [DLA 748-1] libupnp4 security update

2016-12-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libupnp4 Version: 1.8.0~svn20100507-1.2+deb7u1 CVE ID : CVE-2016-8863 Scott Tenaglia discovered a heap-based buffer overflow in libupnp4, a portable SDK for UPnP Devices. That can lead to denial of service or remote

[SECURITY] [DLA 746-2] tomcat6 regression update

2016-12-17 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat6 Version: 6.0.45+dfsg-1~deb7u5 Debian Bug : 848492 The last security update introduced a regression due to the use of StringManager in the ResourceLinkFactory class. The code was removed again since it is not stri

[SECURITY] [DLA 753-1] tomcat7 security update

2016-12-18 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u8 CVE ID : CVE-2016-9774 Debian Bug : 845393 845425 846298 Paul Szabo discovered a potential privilege escalation that could be exploited in the situation envisaged in DLA-622-1. Th

[SECURITY] [DLA 761-1] python-bottle security update

2016-12-24 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: python-bottle Version: 0.10.11-1+deb7u2 CVE ID : CVE-2016-9964 Debian Bug : 848392 It was discovered that bottle, a WSGI-framework for the Python programming language, did not properly filter "\r\n" sequences whe

[SECURITY] [DLA 763-1] squid3 security update

2016-12-25 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: squid3 Version: 3.1.20-2.2+deb7u7 CVE ID : CVE-2016-10002 Debian Bug : 848493 Saulius Lapinskas from Lithuanian State Social Insurance Fund Board discovered that Squid3, a fully featured web proxy cache, does not

[SECURITY] [DLA 766-1] libcrypto++ security update

2016-12-27 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libcrypto++ Version: 5.6.1-6+deb7u3 CVE ID : CVE-2016-9939 Debian Bug : 848009 Gergely Gábor Nagy from Tresorit discovered that libcrypto++, a C++ cryptographic library, contained a bug in several ASN.1 parsing r

[SECURITY] [DLA 779-1] tomcat7 security update

2017-01-10 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u9 CVE ID : CVE-2016-8745 Debian Bug : 849949 A bug in the error handling of the send file code for the NIO HTTP connector resulted in the current Processor object being added to the

[SECURITY] [DLA 781-1] asterisk security update

2017-01-12 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: asterisk Version: 1:1.8.13.1~dfsg1-3+deb7u5 CVE ID : CVE-2014-2287 CVE-2016-7551 Debian Bug : 838832 741313 Two security vulnerabilities were discovered in Asterisk, an Open Source PBX and telephony toolkit. CVE

[SECURITY] [DLA 761-2] python-bottle regression update

2017-01-15 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: python-bottle Version: 0.10.11-1+deb7u3 Debian Bug : 850176 The update for python-bottle issued as DLA 761-1 would cause a crash if a unicode string was used in a header. Updated packages are now available to correct thi

[SECURITY] [DLA 792-1] libphp-swiftmailer security update

2017-01-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libphp-swiftmailer Version: 4.1.5-1+deb7u1 CVE ID : CVE-2016-10074 Debian Bug : 849626 Dawid Golunski from legalhackers-com [1] discovered that the mail transport in Swift Mailer allowed remote attackers to pass

[SECURITY] [DLA 793-1] opus security update

2017-01-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: opus Version: 0.9.14+20120615-1+nmu1+deb7u1 CVE ID : CVE-2017-0381 Debian Bug : 851612 A remote code execution vulnerability was discovered in opus, an audio codec, that could enable an attacker using a specially

[SECURITY] [DLA 794-1] groovy security update

2017-01-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: groovy Version: 1.8.6-1+deb7u2 CVE ID : CVE-2016-6814 Debian Bug : 851408 It was found that a flaw in Apache Groovy, a dynamic language for the Java Virtual Machine, allows remote code execution wherever deserial

[SECURITY] [DLA 797-1] mysql-5.5 security update

2017-01-24 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: mysql-5.5 Version: 5.5.54-0+deb7u1 CVE ID : CVE-2017-3238 CVE-2017-3243 CVE-2017-3244 CVE-2017-3258 CVE-2017-3265 CVE-2017-3291 CVE-2017-3312 CVE-2017-3313 CVE-2017-3317

[SECURITY] [DLA 781-2] asterisk regression update

2017-01-27 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: asterisk Version: 1:1.8.13.1~dfsg1-3+deb7u6 CVE ID : CVE-2014-2287 Brad Barnett found that the recent security update of Asterisk could cause immediate SIP termination due to an incomplete fix for CVE-2014-2287. For

[SECURITY] [DLA 813-1] wordpress security update

2017-02-01 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wordpress Version: 3.6.1+dfsg-1~deb7u13 CVE ID : CVE-2017-5488 CVE-2017-5489 CVE-2017-5490 CVE-2017-5491 CVE-2017-5492 CVE-2017-5493 CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 Debian B

[SECURITY] [DLA 820-1] viewvc security update

2017-02-09 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: viewvc Version: 1.1.5-1.4+deb7u1 CVE ID : CVE-2017-5938 Debian Bug : 854681 Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This is

[SECURITY] [DLA 823-1] tomcat7 security update

2017-02-14 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u10 CVE ID : not yet available Debian Bug : 854551 It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may resu

[SECURITY] [DLA 825-1] spice security update

2017-02-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: spice Version: 0.11.0-1+deb7u4 CVE ID : CVE-2016-9577 CVE-2016-9578 Debian Bug : 854336 Several vulnerabilities were discovered in spice, a SPICE protocol client and server library. The Common Vulnerabilities and

[SECURITY] [DLA 823-2] tomcat7 regression update

2017-02-22 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: tomcat7 Version: 7.0.28-4+deb7u11 CVE ID : CVE-2017-6056 Debian Bug : 854551 The update for tomcat7 issued as DLA-823-1 caused that the server could return HTTP 400 errors under certain circumstances. Updated pac

[SECURITY] [DLA 834-1] phpmyadmin security update

2017-02-23 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: phpmyadmin Version: 4:3.4.11.1-2+deb7u8 CVE ID : CVE-2016-6621 A server-side request forgery vulnerability was reported for the setup script in phpmyadmin, a MYSQL web administration tool. This flaw may allow an unau

[SECURITY] [DLA 835-1] cakephp security update

2017-02-24 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: cakephp Version: 1.3.15-1+deb7u2 CVE ID : CVE-2016-4793 Dawid Golunski from legalhackers.com discovered that cakephp, an application development framework for PHP, contains a vulnerability that allows attackers to sp

[SECURITY] [DLA 840-1] libplist security update

2017-02-28 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libplist Version: 1.8-1+deb7u2 CVE ID : CVE-2017-5834 CVE-2017-5835 Debian Bug : 854000 Several vulnerabilities were discovered in libplist, a library for reading and writing the Apple binary and XML property lis

[SECURITY] [DLA 846-1] libzip-ruby security update

2017-03-06 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libzip-ruby Version: 0.9.4-1+deb7u1 CVE ID : CVE-2017-5946 Debian Bug : 856269 It was discovered that libzip-ruby, a Ruby module for reading and writing zip files, is prone to a directory traversal vulnerability.

[SECURITY] [DLA 853-1] pidgin security update

2017-03-11 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: pidgin Version: 2.10.10-1~deb7u3 CVE ID : CVE-2017-2640 It was discovered that an invalid XML file can trigger an out-of-bound memory access in Pidgin, a multi-protocol instant messaging client, when it is sent by a

[SECURITY] [DLA 855-1] roundcube security update

2017-03-13 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: roundcube Version: 0.7.2-9+deb7u6 CVE ID : CVE-2017-6820 Debian Bug : 857473 Roundcube, a webmail solution for IMAP servers, was susceptible to a cross-site-scripting (XSS) vulnerability via a crafted Cascading S

[SECURITY] [DLA 860-1] wordpress security update

2017-03-17 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: wordpress Version: 3.6.1+dfsg-1~deb7u14 CVE ID : CVE-2017-6814 CVE-2017-6815 CVE-2017-6816 Debian Bug : 857026 Several vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities

[SECURITY] [DLA 870-1] libplist security update

2017-03-24 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libplist Version: 1.8-1+deb7u3 CVE ID : CVE-2017-6435 CVE-2017-6436 CVE-2017-6439 More vulnerabilities were discovered in libplist, a library for reading and writing the Apple binary and XML property lists format. A

[SECURITY] [DLA 872-1] xrdp security update

2017-03-27 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: xrdp Version: 0.5.0-2+deb7u1 CVE ID : CVE-2017-6967 Debian Bug : 858143 It was discovered that xrdp, a Remote Desktop Protocol (RDP) server, calls the PAM function auth_start_session() in an incorrect location, l

[SECURITY] [DLA 875-1] php5 security update

2017-03-27 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: php5 Version: 5.4.45-0+deb7u8 CVE ID : CVE-2016-7478 CVE-2016-7479 CVE-2017-7272 Several issues have been discovered in PHP (recursive acronym for PHP: Hypertext Preprocessor), a widely-used open source general-purpo

[SECURITY] [DLA 888-1] logback security update

2017-04-07 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: logback Version: 1:1.0.4-1+deb7u1 CVE ID : CVE-2017-5929 Debian Bug : 857343 It was discovered that logback, a flexible logging library for Java, would deserialize data from untrusted sockets which may lead to th

[SECURITY] [DLA 893-1] bouncycastle security update

2017-04-10 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bouncycastle Version: 1.44+dfsg-3.1+deb7u2 CVE ID : CVE-2015-6644 An information disclosure vulnerability was discovered in Bouncy Castle, a Java library which consists of various cryptographic algorithms. The Galois

[SECURITY] [DLA 899-1] feh security update

2017-04-17 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: feh Version: 2.3-2+deb7u1 CVE ID : CVE-2017-7875 Debian Bug : 860367 Tobias Stoeckmann discovered it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message.

[SECURITY] [DLA 900-1] freetype security update

2017-04-17 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: freetype Version: 2.4.9-1.1+deb7u5 CVE ID : CVE-2016-10328 Debian Bug : 860303 The Freetype 2 font engine was vulnerable to an out-of-bounds write caused by a heap-based buffer overflow in the cff_parser_run func

  1   2   3   4   5   6   >