[SECURITY] [DLA 599-1] cracklib2 security update

2016-08-20 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: cracklib2 Version: 2.8.19-3+deb7u1 CVE ID : CVE-2016-6318 Debian Bug : 834502 It was discovered that there was a stack-based buffer overflow when parsing large GECOS fields in cracklib2, a pro-active password

[SECURITY] [DLA 598-1] suckless-tools security update

2016-08-20 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: suckless-tools Version: 38-2+deb7u1 CVE ID : CVE-2016-6866 It was discovered that the slock screen locking tool would segfault when the user's account had been disabled. slock called crypt(3) and used the return