Debian 10260 Published by

The following updates has been released for Debian 7 LTS:

DLA 1101-1: emacs23 security update
DLA 1102-1: apache2 security update
DLA 1103-1: bluez security update
DLA 1104-1: newsbeuter security update



DLA 1101-1: emacs23 security update




Package : emacs23
Version : 23.4+1-4+deb7u1
CVE ID : CVE-2017-14482

Charles A. Roelli discovered that Emacs is vulnerable to arbitrary code
execution when rendering text/enriched MIME data (e.g. when using
Emacs-based mail clients).

For Debian 7 "Wheezy", these problems have been fixed in version
23.4+1-4+deb7u1.

We recommend that you upgrade your emacs23 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


DLA 1102-1: apache2 security update




Package : apache2
Version : 2.2.22-13+deb7u12
CVE ID : CVE-2017-9798
Debian Bug : 876109

Hanno Boeck discovered that incorrect parsing of Limit directives of
.htaccess files by the Apache HTTP Server could result in memory
disclosure.

For Debian 7 "Wheezy", these problems have been fixed in version
2.2.22-13+deb7u12.

We recommend that you upgrade your apache2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


DLA 1103-1: bluez security update




Package : bluez
Version : 4.99-2+deb7u1
CVE ID : CVE-2017-1000250
Debian Bug : 875633

The SDP server in BlueZ is vulnerable to an information disclosure
vulnerability which allows remote attackers to obtain sensitive information
from the bluetoothd process memory. This vulnerability lies in the processing
of SDP search attribute requests.

For Debian 7 "Wheezy", these problems have been fixed in version
4.99-2+deb7u1.

We recommend that you upgrade your bluez packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


DLA 1104-1: newsbeuter security update




Package : newsbeuter
Version : 2.5-2+deb7u3
CVE ID : CVE-2017-14500
Debian Bug : 876004

It was discovered that podbeuter, the podcast fetcher in newsbeuter, a
text-mode RSS feed reader, did not properly escape the name of the media
enclosure (the podcast file), allowing a remote attacker to run an
arbitrary shell command on the client machine. This is only exploitable
if the file is also played in podbeuter.

For Debian 7 "Wheezy", these problems have been fixed in version
2.5-2+deb7u3.

We recommend that you upgrade your newsbeuter packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS