Debian 9859 Published by

The following updates has been released for Debian:

[DSA 3530-1] tomcat6 security update
[DSA 3531-1] chromium-browser security update



[DSA 3530-1] tomcat6 security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3530-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
March 25, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : tomcat6
CVE ID : CVE-2013-4286 CVE-2013-4322 CVE-2013-4590 CVE-2014-0033
CVE-2014-0075 CVE-2014-0096 CVE-2014-0099 CVE-2014-0119
CVE-2014-0227 CVE-2014-0230 CVE-2014-7810 CVE-2015-5174
CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706
CVE-2016-0714 CVE-2016-0763

Multiple security vulnerabilities have been fixed in the Tomcat servlet
and JSP engine, which may result on bypass of security manager
restrictions, information disclosure, denial of service or session
fixation.

For the oldstable distribution (wheezy), these problems have been fixed
in version 6.0.45+dfsg-1~deb7u1.

We recommend that you upgrade your tomcat6 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

[DSA 3531-1] chromium-browser security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3531-1 security@debian.org
https://www.debian.org/security/ Michael Gilbert
March 25, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : chromium-browser
CVE ID : CVE-2016-1646 CVE-2016-1647 CVE-2016-1648 CVE-2016-1649
CVE-2016-1650

Several vulnerabilities have been discovered in the chromium web browser.

CVE-2016-1646

Wen Xu discovered an out-of-bounds read issue in the v8 library.

CVE-2016-1647

A use-after-free issue was discovered.

CVE-2016-1648

A use-after-free issue was discovered in the handling of extensions.

CVE-2016-1649

lokihardt discovered a buffer overflow issue in the Almost Native
Graphics Layer Engine (ANGLE) library.

CVE-2016-1650

The chrome development team found and fixed various issues during
internal auditing. Also multiple issues were fixed in the v8
javascript library, version 4.9.385.33.

For the stable distribution (jessie), these problems have been fixed in
version 49.0.2623.108-1~deb8u1.

For the testing distribution (stretch), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 49.0.2623.108-1.

We recommend that you upgrade your chromum-browser packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/