[SECURITY] [DLA 2310-1] thunderbird security update

2020-08-02 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

- -
Debian LTS Advisory DLA-2310-1debian-...@lists.debian.org
https://www.debian.org/lts/security/   Emilio Pozuelo Monfort
August 02, 2020   https://wiki.debian.org/LTS
- -

Package: thunderbird
Version: 1:68.11.0-1~deb9u1
CVE ID : CVE-2020-6463 CVE-2020-6514 CVE-2020-15652 CVE-2020-15659

Multiple security issues have been found in Thunderbird which could
result in denial of service or potentially the execution of arbitrary
code.

For Debian 9 stretch, these problems have been fixed in version
1:68.11.0-1~deb9u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-BEGIN PGP SIGNATURE-

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl8nN5cACgkQnUbEiOQ2
gwLUphAAqSzH6KPTGjU0eF4KXjx8Umk520Yxl/ZqWM7GxSCyYyr9qXNDcWf3X+W4
fFGMgEhOYIoh7oIB9o6+Yuiy7nVLagbAb5YbfKUM6NGufk/0U/CZkXognpk6VEUM
DVsYQfmD3rhJOc117th0EuGVqJ16VD6Un+HzkW9bhnJDqXxl/MR+8UrRwXUnAUVp
0AgrBU3XqMowr5UQW3CvP/S96IspkhkWj8z6dy0WJZw5arD2hKi9hxH+VXUV71lO
5RbDUu1Ns1Jm3x0P004h4eGGtdLxJEjUKNjFdacNuIfx80EmEpKThrjRVsK7Ct7H
KehMQ6mBZIveLfetMHGUc+yyCpcC+KkTmJsMh+p8vyz+cskCELtGEvbgyxwZEJnn
uhJrYV4upLDesGKeRcsSIuE+cMQUNEZ7TZlkJN5AyFl/ZWdfVee86XrrM94CFLii
V8kVAfpWRn2jAQ8ZCBUgkwGPXNhq0Zmksq9UzljoS2ogXxBNA6EfB/YLPRGx+5if
Xz8vtZsIRd1kU/qte6vjBOJaMT8CdokMtkJi1z4lZRM7XoaENh0n8QWl+Wge57xE
9Xkp9OaXCpLDzxTuFf/BDPYMQubUj0mc/3nwEhxjgqjg594mG0Y+QFFktAEEduY7
chlHMDNsnDKxOeKxBdvSb34YYMdGM1P0NlJjPHlBTaeANJPqmoA=
=Zltv
-END PGP SIGNATURE-



[SECURITY] [DLA 2309-1] evolution-data-server security update

2020-08-02 Thread Adrian Bunk
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

- -
Debian LTS Advisory DLA-2309-1debian-...@lists.debian.org
https://www.debian.org/lts/security/ 
August 02, 2020   https://wiki.debian.org/LTS
- -

Package: evolution-data-server
Version: 3.22.7-1+deb9u2
CVE ID : CVE-2020-16117

In Evolution Data Server a vulnerability was discovered that allowed
a malicious server to crash the mail client.

For Debian 9 stretch, this problem has been fixed in version
3.22.7-1+deb9u2.

We recommend that you upgrade your evolution-data-server packages.

For the detailed security status of evolution-data-server please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/evolution-data-server

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAl8nLWsACgkQiNJCh6LY
mLHi4xAAi+VMdfQqkm9qN1xTFXipDGOimDrPi+W7D8xiC/Z5vLr1GpjT//YuE2UM
0i1ejWfaVa0dnPS/WeM/cpPp3KHZvPETWD8fBnP2jPjAMOJiAZpYXIsB/aC0rcUr
XGCCeywxBr/Jw6YOwSMALS4KKnzZBMt2qzht6o3db0P5xpOejldFN0TRAuiHPABn
7+sSu1mtCaEmDQC8wyWsSX95ClGmgX8oCaC5JZI49YqP+lHRWIpHb7uuMkIWGnvv
NAaEvOybR+HWv03mYsmXTyKCyBzaN3yassWn0MMeY0BoUQLp1cK+Gb0jkGuGDbTU
SlzxXPPZsqKUdb7LJuT9BC+m0epeGj6YWi8Exsc2cUXN1rQeLCwdxb1OCiz/bLuI
8ZjTHugkEjxvHZcoLdX/DbxTsWUJ/cuAS02gTBKPGbwpiDf7BHMw29QGyt05D31r
9P2jiMqWa1+Gkty8WiHGvcfkRKolrVZjOp49DweLlZolnyaz2SnE7UfPLhYQWlyA
MbVu68NqFz6QOdOgrwB/YWFNRiLGIvwox49Yf0YYCe+O4Q7gc5jHO33urWBWAWc3
v6aOnN1RfUHeEsavs2h+VTHOk3X2ymNpiNE8Q5KZhzdnUyHI+fm6/kiCQODtMeBP
ykJTVnn5Rb86BWjOOFy9G8IIDLLfhmJDAUgWNQyfIDGwvLorAsQ=
=LHoo
-END PGP SIGNATURE-