Martin Zobel-Helas | 26 Jul 10:54
Picon
Gravatar

[VUA 33-1] Updated clamav package fixes security flaw


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 33-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org                               Stephen Gran
July 26, 2007                                            Martin Zobel-Helas
---------------------------------------------------------------------------

Package              : clamav
Version              : 0.91.1-0volatile1 and 0.91.1-1~volatile1
Importance           : high
CVE IDs              : CVE-2007-3725

The following security flaw was found and fixed in clamav:

[CVE-2007-2650]: Null pointer dereference in the unrar VM, causing a DoS.

For sarge, an updated clamav package is available in sarge/volatile
as version 0.91.1-0volatile1.

For etch, an updated clamav package is available in etch/volatile 
as version 0.91.1-1~volatile1.

We recommend that you update your system.

This advisory was sent out without builds for arm and s390 architectures
being available for etch/volatile. and without builds for arm, hppa,
m68k, mips, mipsel and sparc being available for sarge/volatile. They
will be released as soon as they are available.

Upgrade Instructions
(Continue reading)

Martin Zobel-Helas | 31 Jul 18:29
Picon
Favicon

[VUA 34-1] Updated tzdata package


---------------------------------------------------------------------------
Debian Volatile Update Announcement VUA 34-1     http://volatile.debian.org
debian-volatile <at> lists.debian.org
July 31, 2007                                            Martin Zobel-Helas
---------------------------------------------------------------------------

Package              : tzdata
Version              : 2007f-1etch1
Importance           : low

The tzdata package in "etch" does not contain up-to-date timezone
information for

  * Cuba
  * Haiti
  * Indiana/Winamac
  * Mongolia
  * New Zealand
  * Syria
  * Turkey
  * Turks & Caicos Islands

For etch, an updated tzdata package is available in etch/volatile 
as version 2007f-1etch1.

We recommend that you update your system.

Upgrade Instructions
--------------------
(Continue reading)


Gmane