[SECURITY] [DLA 589-1] mupdf security update

2016-08-08 Thread Jonas Meurer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: mupdf Version: 0.9-2+deb7u3 CVE ID : CVE-2016-6525 Debian Bug : 833417 A flaw was discovered in the pdf_load_mesh_params() function allowing out-of-bounds write access to memory locations. With carefully crafted

[SECURITY] [DLA 588-1] mongodb security update

2016-08-08 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: mongodb Version: 2.0.6-1+deb7u1 CVE ID : CVE-2016-6494 Debian Bug : 832908, 833087 Two security related problems have been found in the mongodb package, related to logging. CVE-2016-6494 World-readable .dbshel