[SECURITY] [DLA 1319-1] firefox-esr security update

2018-03-26 Thread Emilio Pozuelo Monfort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: firefox-esr Version: 52.7.2esr-1~deb7u1 CVE ID : CVE-2018-5146 CVE-2018-5147 Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execu

[SECURITY] [DLA 1318-1] irssi security update

2018-03-26 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: irssi Version: 0.8.15-5+deb7u6 CVE ID : CVE-2018-7051 Debian Bug : #890677 It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when prin

[SECURITY] [DLA 1317-1] net-snmp security update

2018-03-26 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: net-snmp Version: 5.7.2.1+dfsg-1+deb8u1 CVE ID : CVE-2018-1000116 Debian Bug : #894110 It was discovered that there was a heap corruption vulnerability in the net-snmp framework which exchanges server management