Debian 10260 Published by

The following security updates has been released for Debian:

[DLA 458-1] mplayer2 security update
[DSA 3569-1] openafs security update



[DLA 458-1] mplayer2 security update

Package : mplayer2
Version : 2.0-554-gf63dbad-1+deb7u1
CVE ID : CVE-2016-4352

Mplayer2 is crashing when playing a fuzzed gif file. The gif demuxes
assumes in many places that width*height is

[DSA 3569-1] openafs security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3569-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
May 05, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openafs
CVE ID : CVE-2015-8312 CVE-2016-2860

Two vulnerabilities were discovered in openafs, an implementation of the
distributed filesystem AFS. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2015-8312

Potential denial of service caused by a bug in the pioctl
logic allowing a local user to overrun a kernel buffer with a
single NUL byte.

CVE-2016-2860

Peter Iannucci discovered that users from foreign Kerberos realms
can create groups as if they were administrators.

For the stable distribution (jessie), these problems have been fixed in
version 1.6.9-2+deb8u5.

For the testing distribution (stretch), these problems have been fixed
in version 1.6.17-1.

For the unstable distribution (sid), these problems have been fixed in
version 1.6.17-1.

We recommend that you upgrade your openafs packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/