Debian 9902 Published by

The following updates has been released for Debian GNU/Linux 7 Extended LTS:

ELA-166-1 libpng security update
ELA-167-1 cups security update



ELA-166-1: libpng security update

Package: libpng
Version: 1.2.49-1+deb7u3
Related CVE: CVE-2016-10087

Patrick Keshishian found a null pointer dereference in a function of libpng, a library to handle PNG files.

For Debian 7 Wheezy, these problems have been fixed in version 1.2.49-1+deb7u3.

We recommend that you upgrade your libpng packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

ELA-167-1: cups security update

Package: cups
Version: 1.5.3-5+deb7u11
Related CVE: CVE-2018-4300

An issue was found in cups, the Common UNIX Printing System™. Linux session cookies used a predictable random number seed.

This CVE is sometimes referenced as CVE-2018-4700. Please only use CVE-2018-4300 for it.

For Debian 7 Wheezy, these problems have been fixed in version 1.5.3-5+deb7u11.

We recommend that you upgrade your cups packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/