[SECURITY] [DLA-1474-1] openssh security update

2018-08-21 Thread Chris Lamb
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: openssh Version: 1:6.7p1-5+deb8u5 CVE ID : CVE-2018-15473 Debian Bug : #906236 It was discovered that there was a user enumeration vulnerability in OpenSSH. A remote attacker couldtest whether a certain user

[SECURITY] [DLA 1473-1] otrs2 security update

2018-08-21 Thread Markus Koschany
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: otrs2 Version: 3.3.18-1+deb8u5 CVE ID : CVE-2018-14593 Francesco Sirocco discovered a privilege escalation flaw in otrs2, the Open Ticket Request System. An attacker who is logged into OTRS as a user may escalate