[Secure-testing-team] Bug#799073: qemu: CVE-2015-5278: Infinite loop in ne2000_receive() function

2015-09-15 Thread Salvatore Bonaccorso
Source: qemu Version: 1.1.2+dfsg-6a Severity: important Tags: security upstream patch Hi, the following vulnerability was published for qemu. CVE-2015-5278[0]: net: avoid infinite loop when receiving packets > Qemu emulator built with the NE2000 NIC emulation support is > vulnerable to an

[Secure-testing-team] Bug#799074: qemu: CVE-2015-5279: Heap overflow vulnerability in ne2000_receive() function

2015-09-15 Thread Salvatore Bonaccorso
Source: qemu Version: 1.1.2+dfsg-6a Severity: important Tags: security upstream patch Hi, the following vulnerability was published for qemu. CVE-2015-5279[0]: add checks to validate ring buffer pointers > Qemu emulator built with the NE2000 NIC emulation support is > vulnerable to a heap

[Secure-testing-team] Bug#799096: mediawiki: CVE-2015-6727 CVE-2015-6728 CVE-2015-6729 CVE-2015-6730

2015-09-15 Thread Salvatore Bonaccorso
Source: mediawiki Version: 1:1.19.5-1 Severity: important Tags: security upstream Hi, the following vulnerabilities were published for mediawiki. CVE-2015-6727[0]: | The Special:DeletedContributions page in MediaWiki before 1.23.10, | 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote