Debian 9844 Published by

The following security update has been released for Debian GNU/Linux:

Debian GNU/Linux 7 LTS:
DLA 1063-1: extplorer security update

Debian GNU/Linux 8 and 9:
DSA 3950-1: libraw security update



DLA 1063-1: extplorer security update

Package : extplorer
Version : 2.1.0b6+dfsg.3-4+deb7u5
CVE ID : CVE-2017-12756


CVE-2017-12756
Fix command inject in transfer from another server in extplorer
2.1.9 and prior allows attacker to inject command via the
userfile[0] parameter.


For Debian 7 "Wheezy", these problems have been fixed in version
2.1.0b6+dfsg.3-4+deb7u5.

We recommend that you upgrade your extplorer packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

DSA 3950-1: libraw security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-3950-1 security@debian.org
https://www.debian.org/security/ Luciano Bello
August 21, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libraw
CVE ID : CVE-2017-6886 CVE-2017-6887
Debian Bug : 864183

Hossein Lotfi and Jakub Jirasek from Secunia Research have discovered
multiple vulnerabilities in LibRaw, a library for reading RAW images. An
attacker could cause a memory corruption leading to a DoS (Denial of
Service) with craft KDC or TIFF file.

For the oldstable distribution (jessie), these problems have been fixed
in version 0.16.0-9+deb8u3.

For the stable distribution (stretch), these problems have been fixed in
version 0.17.2-6+deb9u1.

We recommend that you upgrade your libraw packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/