Debian 9894 Published by

The following Debian updates has been released today:

[DLA 64-1] curl security update
[DSA 3036-1] mediawiki security update
[DSA 3037-1] icedove security update



[DLA 64-1] curl security update

Package : curl
Version : 7.21.0-2.1+squeeze9
CVE ID : CVE-2014-3613

CVE-2014-3613

By not detecting and rejecting domain names for partial literal IP
addresses properly when parsing received HTTP cookies, libcurl can
be fooled to both sending cookies to wrong sites and into allowing
arbitrary sites to set cookies for others.

[DSA 3036-1] mediawiki security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3036-1 security@debian.org
http://www.debian.org/security/ Thijs Kinkhorst
September 26, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : mediawiki
Debian Bug : 762754

It was discovered that MediaWiki, a wiki engine, did not sufficiently
filter CSS in uploaded SVG files, allowing for cross site scripting.

For the stable distribution (wheezy), this problem has been fixed in
version 1:1.19.19+dfsg-0+deb7u1.

For the unstable distribution (sid), this problem has been fixed in
version 1:1.19.19+dfsg-1.

We recommend that you upgrade your mediawiki packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

[DSA 3037-1] icedove security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3037-1 security@debian.org
http://www.debian.org/security/ Yves-Alexis Perez
September 26, 2014 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : icedove
CVE ID : CVE-2014-1568

Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the
Mozilla Network Security Service library, embedded in Wheezy's Icedove),
was parsing ASN.1 data used in signatures, making it vulnerable to a
signature forgery attack.

An attacker could craft ASN.1 data to forge RSA certificates with a valid
certification chain to a trusted CA.

For the stable distribution (wheezy), this problem has been fixed in
version 24.8.1esr-1~deb7u1.

For the testing distribution (jessie) and unstable distribution (sid),
Icedove uses the system NSS library, handled in DSA 3033-1.

We recommend that you upgrade your icedove packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/