[SECURITY] [DLA 253-1] libwmf security update

2015-06-26 Thread Guido Günther
Package: libwmf Version: 0.2.8.4-6.2+deb6u1 CVE ID : CVE-2015-0848 CVE-2015-4588 Debian Bug : #787644 The following vulnerabilities were discovered in the Windows Metafile conversion library when reading BMP images embedded into WMF files: CVE-2015-0848 A heap ove

[SECURITY] [DLA 254-1] librack-ruby security update

2015-06-26 Thread Guido Günther
Package: librack-ruby Version: 1.1.0-4+squeeze3 CVE ID : CVE-2015-3225 There is a potential denial of service vulnerability in Rack, a modular Ruby webserver interface. Carefully crafted requests can cause a `SystemStackError` and cause a denial of service attack by exploi