[SECURITY] [DLA 482-1] libgd2 security update

2016-05-19 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: libgd2 Version: 2.0.36~rc1~dfsg-6.1+deb7u3 CVE ID : CVE-2015-8874 Debian Bug : 824627 It was discovered that there was a stack consumption vulnerability in the libgd2 graphics library which allowed remote attacke

[SECURITY] [DLA 483-1] expat security update

2016-05-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: expat Version: 2.1.0-1+deb7u3 CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, a XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows d