[SECURITY] [DLA 670-1] linux security update

2016-10-19 Thread Ben Hutchings
Package: linux Version: 3.2.82-1 CVE ID : CVE-2015-8956 CVE-2016-5195 CVE-2016-7042 CVE-2016-7425 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2015-8956 It was

[SECURITY] [DLA 671-1] libxvmc security update

2016-10-19 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxvmc Version: 2:1.0.7-1+deb7u3 CVE ID : CVE-2016-7953 CVE-2016-7953 If an empty string is received from an x-server, do not underrun the buffer by accessing "rep.nameLen - 1" unconditionally, which

[SECURITY] [DLA 667-1] libxv security update

2016-10-19 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: libxv Version: 2:1.0.7-1+deb7u2 CVE ID : CVE-2016-5407 Debian Bug : 840438 Tobias Stoeckmann from the OpenBSD project has discovered a number of issues in the way various X client libraries handle the responses