[Secure-testing-team] Bug#870338: timidity: CVE-2017-11546 CVE-2017-11547 CVE-2017-11549

2017-08-01 Thread Salvatore Bonaccorso
Source: timidity Version: 2.13.2-40.2 Severity: important Tags: upstream security Hi, the following vulnerabilities were published for timidity. All three issues seem to affect the same set of versions in Debian, thus filling only one bugreport: CVE-2017-11546[0]: | The insert_note_steps

[Secure-testing-team] Bug#870333: libid3tag: CVE-2017-11551

2017-08-01 Thread Salvatore Bonaccorso
Source: libid3tag Version: 0.15.1b-11 Severity: normal Tags: security upstream Hi, the following vulnerability was published for libid3tag. CVE-2017-11551[0]: | The id3_field_parse function in field.c in libid3tag 0.15.1b allows | remote attackers to cause a denial of service (OOM) via a

[Secure-testing-team] Bug#870341: libvorbis: CVE-2017-11333

2017-08-01 Thread Salvatore Bonaccorso
Source: libvorbis Version: 1.3.5-4 Severity: important Tags: security upstream Hi, the following vulnerability was published for libvorbis, can you double-check the report. CVE-2017-11333[0]: | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis | 1.3.5 allows remote

[Secure-testing-team] Bug#870342: libvorbis: CVE-2017-11735

2017-08-01 Thread Salvatore Bonaccorso
Source: libvorbis Version: 1.3.5-4 Severity: important Tags: upstream security Hi, the following vulnerability was published for libvorbis, can you please double-check the report. CVE-2017-11735[0]: | The vorbis_block_clear function in lib/block.c in Xiph.Org libvorbis | 1.3.5 allows remote

[Secure-testing-team] Bug#870353: cacti: CVE-2017-12065

2017-08-01 Thread Salvatore Bonaccorso
Source: cacti Version: 1.1.15+ds1-1 Severity: important Tags: security upstream patch Forwarded: https://github.com/Cacti/cacti/issues/877 Hi, the following vulnerability was published for cacti. CVE-2017-12065[0]: | spikekill.php in Cacti before 1.1.16 might allow remote attackers to | execute

[Secure-testing-team] Bug#870406: libmad: CVE-2017-11552

2017-08-01 Thread Salvatore Bonaccorso
Source: libmad Version: 0.15.1b-7 Severity: important Tags: security upstream Hi, the following vulnerability was published for libmad. CVE-2017-11552[0]: | The mad_decoder_run function in decoder.c in libmad 0.15.1b allows | remote attackers to cause a denial of service (memory corruption) via