[SECURITY] [DLA 960-1] imagemagick security update

2017-05-28 Thread Roberto C. Sanchez
Package: imagemagick Version: 6.7.7.10-5+deb7u14 CVE ID : CVE-2014-8354 CVE-2014-8355 CVE-2014-8562 CVE-2014-8716 CVE-2014-9841 CVE-2015-8900 CVE-2015-8901 CVE-2015-8902 CVE-2015-8903 CVE-2017-7941 CVE-2017-7943 CVE-2017-8343

[SECURITY] [DLA 959-1] libical security update

2017-05-28 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libical Version: 0.48-2+deb7u1 CVE ID : CVE-2016-5824 CVE-2016-9584 Debian Bug : #860451, #852034 It was discovered that there was a use-after-free vulnerability in the libical iCalendar library. Remote attackers

[SECURITY] [DLA 958-1] libonig security update

2017-05-28 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libonig Version: 5.9.1-1+deb7u1 CVE ID : CVE-2017-9224 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 CVE-2017-9229 Debian Bug : 863312 863314 863315 863316 863318 CVE-2017-9224 An issue was dis

[SECURITY] [DLA 957-1] bind9 security update

2017-05-28 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: bind9 Version: 1:9.8.4.dfsg.P1-6+nmu2+deb7u16 CVE ID : CVE-2017-3136 CVE-2017-3137 CVE-2017-3138 CVE-2017-3136 Oleg Gorokhov of Yandex discovered that BIND does not properly handle certain queries when usin

[SECURITY] [DLA 956-1] libsndfile security update

2017-05-28 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libsndfile Version: 1.0.25-9.1+deb7u2 CVE ID : CVE-2017-8361 CVE-2017-8362 CVE-2017-8363 CVE-2017-8365 CVE-2017-8361 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to