[SECURITY] [DLA 971-1] nss security update

2017-05-31 Thread Ola Lundqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: nss Version: 2:3.26-1+debu7u4 CVE ID : CVE-2017-7502 Debian Bug : 863839 CVE-2017-7502 A null pointer dereference vulnerability in NSS was found when server receives empty SSLv2 messages. This issue was

[SECURITY] [DLA 965-1] qemu-kvm security update

2017-05-31 Thread Guido Günther
Package: qemu-kvm Version: 1.1.2+dfsg-6+deb7u22 CVE ID : CVE-2016-9602 CVE-2017-7377 CVE-2017-7471 CVE-2017-7493 CVE-2017-8086 Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86