The following updates has been released for Debian GNU/Linux 8 LTS:
DLA 1753-3: proftpd-dfsg regression update
DLA 1798-1: jackson-databind security update
DLA 1753-3: proftpd-dfsg regression update
DLA 1798-1: jackson-databind security update
DLA 1753-3: proftpd-dfsg regression update
Package : proftpd-dfsg
Version : 1.3.5e+r1.3.5-2+deb8u2
Debian Bug : 929020
The update of proftpd-dfsg issued as DLA-1753-1 caused a regression
when the creation of a directory failed during sftp transfer. The sftp
session would be terminated instead of failing gracefully due to a
non-existing debug logging function.
For Debian 8 "Jessie", this problem has been fixed in version
1.3.5e+r1.3.5-2+deb8u2.
We recommend that you upgrade your proftpd-dfsg packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
DLA 1798-1: jackson-databind security update
Package : jackson-databind
Version : 2.4.2-2+deb8u6
CVE ID : CVE-2019-12086
Debian Bug : 929177
A Polymorphic Typing issue was discovered in jackson-databind, a JSON
library for Java. When Default Typing is enabled (either globally or
for a specific property) for an externally exposed JSON endpoint, the
service has the mysql-connector-java jar (8.0.14 or earlier) in the
classpath, and an attacker can host a crafted MySQL server reachable
by the victim, an attacker can send a crafted JSON message that allows
them to read arbitrary local files on the server. This occurs because of
missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
For Debian 8 "Jessie", this problem has been fixed in version
2.4.2-2+deb8u6.
We recommend that you upgrade your jackson-databind packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS