The following security update has been released for Debian GNU/Linux:
Debian GNU/Linux 7 LTS:
DLA 1063-1: extplorer security update
Debian GNU/Linux 8 and 9:
DSA 3950-1: libraw security update
Debian GNU/Linux 7 LTS:
DLA 1063-1: extplorer security update
Debian GNU/Linux 8 and 9:
DSA 3950-1: libraw security update
DLA 1063-1: extplorer security update
Package : extplorer
Version : 2.1.0b6+dfsg.3-4+deb7u5
CVE ID : CVE-2017-12756
CVE-2017-12756
Fix command inject in transfer from another server in extplorer
2.1.9 and prior allows attacker to inject command via the
userfile[0] parameter.
For Debian 7 "Wheezy", these problems have been fixed in version
2.1.0b6+dfsg.3-4+deb7u5.
We recommend that you upgrade your extplorer packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
DSA 3950-1: libraw security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3950-1 security@debian.org
https://www.debian.org/security/ Luciano Bello
August 21, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libraw
CVE ID : CVE-2017-6886 CVE-2017-6887
Debian Bug : 864183
Hossein Lotfi and Jakub Jirasek from Secunia Research have discovered
multiple vulnerabilities in LibRaw, a library for reading RAW images. An
attacker could cause a memory corruption leading to a DoS (Denial of
Service) with craft KDC or TIFF file.
For the oldstable distribution (jessie), these problems have been fixed
in version 0.16.0-9+deb8u3.
For the stable distribution (stretch), these problems have been fixed in
version 0.17.2-6+deb9u1.
We recommend that you upgrade your libraw packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/