Debian 9894 Published by

The following updates has been released for Debian GNU/Linux 8 LTS:

DLA 1403-1: zendframework security update
Fixing an issue where remote attackers can conduct SQL injection attacks

DLA 1404-1: lava-server security update
Fixing an issue where a user can ead any file on the server that is readable by lavaserver



DLA 1403-1: zendframework security update




Package : zendframework
Version : 1.12.9+dfsg-2+deb8u7
CVE ID : CVE-2016-4861


CVE-2016-4861
Allowing remote attackers to conduct SQL injection attacks by
leveraging failure to remove comments from an SQL statement
before validation.


For Debian 8 "Jessie", these problems have been fixed in version
1.12.9+dfsg-2+deb8u7.

We recommend that you upgrade your zendframework packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



DLA 1404-1: lava-server security update




Package : lava-server
Version : 2014.09.1-1+deb8u1
CVE ID : CVE-2018-12564


CVE-2018-12564
Using the feature to add URLs in the submit page, a user might be
able to read any file on the server that is readable by lavaserver
and consists of valid yaml.
So with this patch the feature is disabled again.


For Debian 8 "Jessie", these problems have been fixed in version
2014.09.1-1+deb8u1.

We recommend that you upgrade your lava-server packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS