• [SECURITY] [DSA 3766-1] mapserver security update

    From Sebastien Delafond@1:229/2 to All on Thu Jan 19 10:00:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3766-1 [email protected] https://www.debian.org/security/ Sebastien Delafond January 19, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : mapserver
    CVE ID : CVE-2017-5522

    It was discovered that mapserver, a CGI-based framework for Internet
    map services, was vulnerable to a stack-based overflow. This issue
    allowed a remote user to crash the service, or potentially execute
    arbitrary code.

    For the stable distribution (jessie), this problem has been fixed in
    version 6.4.1-5+deb8u3.

    For the unstable distribution (sid), this problem has been fixed in
    version 7.0.4-1.

    We recommend that you upgrade your mapserver packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAliAe+MACgkQEL6Jg/PV nWT/DQgAuLD5VxD8r+Wl0cyTEKle+aBNGDNQlvS5Vmdp4VHqMltD0J+d0p6XVxuL 6wQeTpKmZyyaQ8XDI9VPiWUP5UtMKWAxOT5/waCMJARqUR7SkGqgWKTB8bDcs8Pl oyNRSIkJE4XM+aq14+CMjN+47kTTpbwqYIYFUtXFrqk8tDMD3Rdym18ot+vpkPgI iZmRSUFYKq5QHSjFTcFqPvkchw6xXQXI23nH8msFS4u0BBTRMVTMh3t6eiV9V0lJ xNq6B5Tq2IZb6bmsAABLsnI1WALDzv/l+fSTo8ppm++QczRzm8y1lmgN0qw6f9a0 QtbD++G6sriJurGArx7l9Awernl0XA==
    =KMF2
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)