Just released:
Updates in 2 source package(s), 4 binary package(s):
Source gnupg, binaries: gnupg:amd64 gpgv:amd64
gnupg (1.4.18-7+deb8u5) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* gpg: Sanitize diagnostic with the original file name (CVE-2018-12020)
Source procps, binaries: libprocps3:amd64 procps:amd64
procps (2:3.3.9-9+deb8u1) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* top: Do not default to the cwd in configs_read(). (CVE-2018-1122)
* ps/output.c: Fix outbuf overflows in pr_args() etc. (CVE-2018-1123)
* proc/readproc.c: Fix bugs and overflows in file2strvec(). (CVE-2018-1124)
* pgrep: Prevent a potential stack-based buffer overflow (CVE-2018-1125)
* proc/alloc.*: Use size_t, not unsigned int. (CVE-2018-1126)
https://cloud.debian.org/images/openstack/current-8/
--
Steve McIntyre, Cambridge, UK. steve@einval.com
"Managing a volunteer open source project is a lot like herding
kittens, except the kittens randomly appear and disappear because they
have day jobs." -- Matt Mackall
Attachment:
signature.asc
Description: PGP signature