Debian 9844 Published by

The following updates has been released for Debian GNU/Linux:

[DLA 91-2] tomcat6 regression update
[DSA 3132-1] icedove security update



[DLA 91-2] tomcat6 regression update

Package : tomcat6
Version : 6.0.41-2+squeeze6

This update fixes a "NoSuchElementException" when an XML attribute has an
empty string as value.

[DSA 3132-1] icedove security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3132-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
January 19, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : icedove
CVE ID : CVE-2014-8634 CVE-2014-8638 CVE-2014-8639

Multiple security issues have been found in Icedove, Debian's version of
the Mozilla Thunderbird mail and news client: Multiple memory safety
errors and implementation errors may lead to the execution of arbitrary
code, information leaks or denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 31.4.0-1~deb7u1.

For the upcoming stable distribution (jessie), these problems will be
fixed soon.

For the unstable distribution (sid), these problems have been fixed in
version 31.4.0-1.

We recommend that you upgrade your icedove packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/