[Secure-testing-team] Bug#869171: slirp: out-of-bounds read while parsing dhcp options

2017-07-21 Thread Guido Günther
Package: qemu X-Debbugs-CC: t...@security.debian.org secure-testing-team@lists.alioth.debian.org Severity: important Tags: security Hi, the following vulnerability was published for qemu. CVE-2017-11434[0]: slirp: out-of-bounds read while parsing dhcp options If you fix the vulnerability

[Secure-testing-team] Bug#869173: exec: oob access during dma operation

2017-07-21 Thread Guido Günther
Package: qemu X-Debbugs-CC: t...@security.debian.org secure-testing-team@lists.alioth.debian.org Severity: important Tags: security Hi, the following vulnerability was published for qemu. CVE-2017-11334[0]: exec: oob access during dma operation If you fix the vulnerability please also make

[Secure-testing-team] Bug#869242: CVE-2017-11468

2017-07-21 Thread Moritz Muehlenhoff
Source: docker-registry Severity: important Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11468 Cheers, Moritz ___ Secure-testing-team mailing list Secure-testing-team@lists.alioth.debian.org

[Secure-testing-team] Bug#869220: agrep crash caused by double free

2017-07-21 Thread Stefan Weil
Package: agrep Version: 4.17-9 Severity: important Tags: security patch The following crash can be reproduced (files can be downloaded with base URL https://digi.bib.uni-mannheim.de/periodika/reichsanzeiger/ocr/film/tesseract-4.0.0-alpha.20170703/): $ agrep -2 -l -d '$$' 'Beilage zum Deutſchen'