[Secure-testing-team] Bug#869260: CVE-2017-11368

2017-07-22 Thread Moritz Muehlenhoff
Source: krb5 Severity: grave Tags: security Hi, please see: https://github.com/krb5/krb5/pull/678/commits/a860385dd8fbd239fdb31b347e07f4e6b2fbdcc2 Cheers, Moritz ___ Secure-testing-team mailing list Secure-testing-team@lists.alioth.debian.org

[Secure-testing-team] Bug#869263: libgd2: CVE-2017-7890: Buffer over-read into uninitialized memory

2017-07-22 Thread Salvatore Bonaccorso
Source: libgd2 Version: 2.2.4-2 Severity: important Tags: security upstream Forwarded: https://github.com/libgd/libgd/issues/399 Hi, the following vulnerability was published for libgd2. CVE-2017-7890[0]: Buffer over-read into uninitialized memory If you fix the vulnerability please also make

[Secure-testing-team] Bug#869261: CVE-2017-7537

2017-07-22 Thread Moritz Muehlenhoff
Source: dogtag-pki Severity: grave Tags: security Please see: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7537 Cheers, Moritz ___ Secure-testing-team mailing list Secure-testing-team@lists.alioth.debian.org

[Secure-testing-team] Bug#869404: resiprocate: CVE-2017-11521: Adding too many media connections may lead to memory exhaustion

2017-07-22 Thread Salvatore Bonaccorso
Source: resiprocate Version: 1:1.9.7-5 Severity: grave Tags: upstream security Forwarded: https://github.com/resiprocate/resiprocate/pull/88 Hi, the following vulnerability was published for resiprocate. CVE-2017-11521[0]: | The SdpContents::Session::Medium::parse function in |