[SECURITY] [DLA 344-1] nspr security update

2015-11-19 Thread Santiago Ruano Rincón
Package: nspr Version: 4.8.6-1+squeeze3 CVE ID : CVE-2015-7183 Google security engineer Ryan Sleevi found a vulnerability in the NetScape Portable Runtime Library (NSPR). NSPR allocated memory without specific checks, making it possible for remote attackers to cause a

[SECURITY] [DLA 345-1] strongswan security update

2015-11-19 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: strongswan Version: 4.4.1-5.8 CVE ID : CVE-2015-8023 Tobias Brunner found an authentication bypass vulnerability in strongSwan, an IKE/IPsec suite. Due to insufficient validation of its local state the server