Debian 9858 Published by

Two updated has been released for Debian 6 LTS:

[DLA 258-1] jqueryui security update
[DLA 259-1] shibboleth-sp2 security update



[DLA 258-1] jqueryui security update

Package : jqueryui
Version : 1.8.dfsg-3+deb6u1
CVE ID : CVE-2010-5312

Shadowman131 discovered that jqueryui, a JavaScript UI library for
dynamic web applications, failed to properly sanitize its "title"
option. This would allow a remote attacker to inject arbitrary code
through cross-site scripting.

[DLA 259-1] shibboleth-sp2 security update

Package : shibboleth-sp2
Version : 2.3.1+dfsg-5+deb6u1
CVE ID : CVE-2015-2684

A denial of service vulnerability was found in the Shibboleth (an
federated identity framework) Service Provider. When processing certain
malformed SAML message generated by an authenticated attacker, the daemon
could crash.

For the Debian 6 “Squeeze” distribution, this problem has been fixed in
version 2.3.1+dfsg-5+deb6u1.

We recommend that you upgrade your shibboleth-sp2 packages.