[SECURITY] [DLA 1141-1] mysql-5.5 security update

2017-10-19 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: mysql-5.5 Version: 5.5.58-0+deb7u1 CVE ID : CVE-2017-10268 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 Debian Bug : 878402 Several issues have been discovered in the MySQL database server. The vulnerabilities

[SECURITY] [DLA 1138-1] nss security update

2017-10-19 Thread Roberto C . Sánchez
Package: nss Version: 2:3.26-1+debu7u5 CVE ID : CVE-2017-7805 Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker

[SECURITY] [DLA 1140-1] graphicsmagick security update

2017-10-19 Thread Brian May
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: graphicsmagick Version: 1.3.16-1.1+deb7u11 CVE ID : CVE-2017-13737 CVE-2017-15277 Immediately after the previous update to graphicsmagick, two more security issues were identified. These updates are included here.