[Secure-testing-team] Bug#704063: ibutils: CVE-2013-2561

2013-03-27 Thread Moritz Muehlenhoff
Package: ibutils Severity: important Tags: security This was assigned CVE-2013-2561: http://seclists.org/fulldisclosure/2013/Mar/87 Cheers, Moritz ___ Secure-testing-team mailing list Secure-testing-team@lists.alioth.debian.org

[Secure-testing-team] Bug#704066: libapache2-mod-ruid2: CVE-2013-1889

2013-03-27 Thread Moritz Muehlenhoff
Package: libapache2-mod-ruid2 Severity: important Tags: security This was assigned CVE-2013-1889: http://www.openwall.com/lists/oss-security/2013/03/22/5 Cheers, Moritz ___ Secure-testing-team mailing list

[Secure-testing-team] Bug#704077: CVE-2013-0336

2013-03-27 Thread Moritz Muehlenhoff
Package: 389-ds Severity: grave Tags: security Please see the following bug for details: https://bugzilla.redhat.com/show_bug.cgi?id=913751 Cheers, Moritz ___ Secure-testing-team mailing list Secure-testing-team@lists.alioth.debian.org

[Secure-testing-team] Bug#704114: asterisk: asterisk security advisories: AST-2013-001 / AST-2013-002 / AST-2013-003

2013-03-27 Thread Salvatore Bonaccorso
Package: asterisk Severity: grave Tags: security patch upstream Hi, the following vulnerabilities were published for asterisk. CVE-2013-2685[0]: Buffer Overflow Exploit Through SIP SDP Header CVE-2013-2686[1]: Denial of Service in HTTP server CVE-2013-2264[2]: Username disclosure in SIP