• [SECURITY] [DSA 3830-1] icu security update

    From Sebastien Delafond@1:229/2 to All on Wed Apr 19 08:50:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3830-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    April 19, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : icu
    CVE ID : CVE-2017-7867 CVE-2017-7868
    Debian Bug : 860314

    It was discovered that icu, the International Components for Unicode
    library, did not correctly validate its input. An attacker could use
    this problem to trigger an out-of-bound write through a heap-based
    buffer overflow, thus causing a denial of service via application
    crash, or potential execution of arbitrary code.

    For the stable distribution (jessie), these problems have been fixed in
    version 52.1-8+deb8u5.

    For the upcoming stable (stretch) and unstable (sid) distributions,
    these problems have been fixed in version 57.1-6.

    We recommend that you upgrade your icu packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlj3ASUACgkQEL6Jg/PV nWQ+2gf/R62V8NNv/1e8fqkv6gOWDanKk0lhJvi6a7O6QyZI9JzZTlnoZ4nIFU4+ NEAfW6zLwp6bP7M+TpSIgtdcu7s1tzsn+hyInq1tHk9eeZ1hFlQQeC/ia4cE+VzH Uej8IiXMtcsissTeEJoC8Tgy6V4kC7NHOkSKx470P/7+DZsXQ14qj2RVytvuxTjE Y9TFW+BTGlWppZJl0ywb8mWBsQu2gStBUbvLAhIDpqN9Q7LnNvj2Zotu4ERFFr1G r2nahvjE3RO27kkM64yvZF+dL23byYQqokjqP//JtnnLGletz/y2WviaNfpmldJb 4Gik5wqyryvaMzMEl9VjDESrzvmz/A==
    =6A8M
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)