[SECURITY] [DLA 1295-1] drupal7 security update

2018-02-28 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: drupal7 Version: 7.14-2+deb7u17 CVE ID : CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6932 Debian Bug : 891152 891150 891153 891154 Multiple vulnerabilities have been found in the Drupal co

[SECURITY] [DLA 1296-1] xmltooling security update

2018-02-28 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package : xmltooling Version : 1.4.2-5+deb7u3 CVE ID : CVE-2018-0489 Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For ad