[SECURITY] [DLA 1767-1] monit security update

2019-04-26 Thread Thorsten Alteholz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: monit Version: 1:5.9-1+deb8u2 CVE ID : CVE-2019-11454 CVE-2019-11455 Zack Flack found several issues in monit, a utility for monitoring and managing daemons or similar programs. CVE-2019-11454 An XSS vulner

[SECURITY] [DLA 1766-1] evolution security update

2019-04-26 Thread Jonas Meurer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Package: evolution Version: 3.12.9~git20141130.241663-1+deb8u1 CVE ID : CVE-2018-15587 Debian Bug : 924616 Hanno Böck discovered that GNOME Evolution is prone to OpenPGP signatures being spoofed for arbitrary messages us

[SECURITY] [DLA 1762-2] systemd regression update

2019-04-26 Thread Mike Gabriel
Package: systemd Version: 215-17+deb8u13 In the recently uploaded systemd security update (215-17+deb8u12 via DLA-1762-1), a regression was discovered in the fix for CVE-2017-18078. The observation of Debian jessie LTS users was, that after upgrading to +deb8u12 temporary files w