[SECURITY] [DLA 945-1] mysql-connector-java security update

2017-05-16 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: mysql-connector-java Version: 5.1.42-1~deb7u1 CVE ID : CVE-2017-3523 CVE-2017-3586 CVE-2017-3589 Several issues were discovered in mysql-connector-java that allow attackers to execute arbitrary code, insert or

[SECURITY] [DLA 944-1] openvpn security update

2017-05-16 Thread Raphael Hertzog
Package: openvpn Version: 2.2.1-8+deb7u4 CVE ID : CVE-2017-7479 Denial of Service due to Exhaustion of Packet-ID counter An authenticated client can cause the server's the packet-id counter to roll over, which would lead the server process to hit an ASSERT() and stop

[SECURITY] [DLA 943-1] deluge security update

2017-05-16 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: deluge Version: 1.3.3-2+nmu1+deb7u2 Debian Bug : #862611 It was discovered that there was a directory traversal attack vulnerability in the web user interface web in the deluge bittorrent client. For Debian 7 "Wheezy",