Debian 9904 Published by

The following Debian updates has been released:

[DLA 60-1] icinga security update
[DLA 61-1] libplack-perl security update
[DSA 3033-1] nss security update
[DSA 3034-1] iceweasel security update



[DLA 60-1] icinga security update

Package : icinga
Version : 1.0.2-2+squeeze2
CVE ID : CVE-2013-7108 CVE-2014-1878

Two fixes for the Classic UI:
- fix off-by-one memory access in process_cgivars() (CVE-2013-7108)
- prevent possible buffer overflows in cmd.cgi (CVE-2014-1878)


[DLA 61-1] libplack-perl security update

Package : libplack-perl
Version : 0.9941-1+deb6u1
CVE ID : CVE-2014-5269

Apply fix for CVE-2014-5269: Plack::App::File would previously strip trailing
slashes off provided paths. This could under specific circumstances lead to
the unintended delivery of files. For details see
https://github.com/plack/Plack/pull/446 .


[DSA 3033-1] nss security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3033-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
September 25, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nss
CVE ID : CVE-2014-1568

Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS
(the Mozilla Network Security Service library) was parsing ASN.1 data
used in signatures, making it vulnerable to a signature forgery attack.

An attacker could craft ASN.1 data to forge RSA certificates with a
valid certification chain to a trusted CA.

For the stable distribution (wheezy), this problem has been fixed in
version 2:3.14.5-1+deb7u2.

For the testing distribution (jessie), this problem has been fixed in
version 2:3.17.1.

For the unstable distribution (sid), this problem has been fixed in
version 2:3.17.1.

We recommend that you upgrade your nss packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

[DSA 3034-1] iceweasel security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3034-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
September 25, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : iceweasel
CVE ID : CVE-2014-1568

Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS
(the Mozilla Network Security Service library, embedded in Wheezy's
Iceweasel package), was parsing ASN.1 data used in signatures, making it
vulnerable to a signature forgery attack.

An attacker could craft ASN.1 data to forge RSA certificates with a
valid certification chain to a trusted CA.

For the stable distribution (wheezy), this problem has been fixed in
version 24.8.1esr-1~deb7u1.

For the testing distribution (jessie) and unstable distribution (sid),
Iceweasel uses the system NSS library, handled in DSA 3033-1.

We recommend that you upgrade your iceweasel packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/