lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20150119165822.GA4559@pisco.westfalen.local>
Date: Mon, 19 Jan 2015 17:58:23 +0100
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 3132-1] icedove security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3132-1                   security@...ian.org
http://www.debian.org/security/                        Moritz Muehlenhoff
January 19, 2015                       http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : icedove
CVE ID         : CVE-2014-8634 CVE-2014-8638 CVE-2014-8639

Multiple security issues have been found in Icedove, Debian's version of
the Mozilla Thunderbird mail and news client: Multiple memory safety
errors and implementation errors may lead to the execution of arbitrary
code, information leaks or denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 31.4.0-1~deb7u1.

For the upcoming stable distribution (jessie), these problems will be
fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 31.4.0-1.

We recommend that you upgrade your icedove packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUvTeUAAoJEBDCk7bDfE42ufEQAISQvgMvZpdvMQdQ687/q6T+
zwApuHz18y2AKg1vKveVCu7+5QfKg8sN2JRGKAQosqVgjjIj3SiLPem6YTrVhO23
iLkAJ6W2vvuZnVV9FfUqvl/6QKD6ll3uTCfsfPWhAJ00mDSkiYgsezVztdk6lwBq
DPs9HRZgRlLUc2adWsWq//Ya6mwyndtzznHeNFzjiN2egWIl0q9BA1blhv2fUS1T
qSqYQ12PWSsXq3v426UMeowAZY5iD1NSfUiIUTRgvIaprJVBo2UpduPRaztlQioA
+Ed0NwSY7aIyuMo4GsXL0uURUFxxUX1TLIa2Ef7OtvA9T8AZXx+38BZm904BSyvQ
SDofFHYPZVzDWP1lj5RFvyzc6seH8rfh9dpvudxJZPdm0drTE33PjwGaxX7qAjv6
SQ1ay6lnVNBUN+PDwznCKQp2tT1dcMpX52Em902gdq9phPp8xst5bl28y4c8uK1j
YO9peTvExMjFaf0R4DdRgAlPk7avdFP1D1Id66e8Tdz4LxLJmavIxwBlTm+BC9Pw
1nBj9yaMvaTlR0rfA4oecwiWZMgg2erEg3tVRr8zPQp4gqHDakEfVtpX3rxY/t33
2TIWvc9KHZeS7FNxsz1ed6GMOcW5Ba5OzFt7qlgICQcolC8jQf1Y6PuTWKZlNhS0
jOXd+kg2FeEMu66Tvow+
=Hiky
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ