[SECURITY] [DLA 697-1] bsdiff security update

2016-11-03 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: bsdiff Version: 4.3-14+deb7u1 CVE ID : CVE-2014-9862 It was discovered that there was an "arbitrary write" vulnerability in bsdiff, a tool to patches between binary files. For Debian 7 "Wheezy", this issue has been

[SECURITY] [DLA 698-1] qemu security update

2016-11-03 Thread Guido Günther
Package: qemu Version: 1.1.2+dfsg-6+deb7u18 CVE ID : CVE-2016-7909 CVE-2016-8909 CVE-2016-8910 CVE-2016-9101 CVE-2016-9102 CVE-2016-9103 CVE-2016-9104 CVE-2016-9105 CVE-2016-9106 Debian Bug : 839834 841950 841955 842455 842463 Several vulnerabilities were discovered in

[SECURITY] [DLA 699-1] xen security update

2016-11-03 Thread Guido Günther
Package: xen Version: 4.1.6.lts1-3 CVE ID : CVE-2016- Xen does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruc