-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3477-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff February 14, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : iceweasel CVE ID : CVE-2016-1523 Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in version 44.0-1. We recommend that you upgrade your iceweasel packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJWwGtJAAoJEBDCk7bDfE42pzMP/1Zk0KZmlZ3odxLivdljj663 Ss6LqvA7kPlvPMSUCndgzmkVPpY2GUAXU/kay9hdskVLLy2fwGLf9zp44+KPDw1y W6BqjW4FWq0ZwrrsvnlmN5hB5jk3jIgh06CaWgmtrZ3JqvcsNdEnKXgWs4K5OHfO cun4JedPeLeYnLs5uhhh3fUXbpZx+nYOMtz/qyppd7xFC7r4ARPwcyc7WoqcJx18 RNNY+SrAz9zDxCcXoQRewEEPgG+BKzP23nSkHJb/BLuoXNEMOMDwyj9Bb5k5tq/q p9Lj9tT9IEph7/xWpj7kr5S0RQNTuODrqNYpejbotW3TUWvniSgnC/jOn+2WCCAx FE34znfFI/OiPMG0JcuQWYvSm7pflA0mrYuxddNMcezibNfzyPG34lFHL2Fe8Ukh eh94RpOzGnz5kM39CQld8w40nRqKRkFRU+8OQgeImw56MJVv5Zmzx2BVntpyEtp9 FkPfFHCnpO9ghCcePiYNc23HS6pSqU1rgvptlYPLz6k5V8WAJPcBh9VrH3JuYpPn qXCudYQOWwQmD4yz3wiBcNo8IjrW7ThuRqmthI4MYkw37yns8ML0J2lzbqxx+ucs +lcOmTO34weKP9U/FO+I6/YllK4xpMnJjW3/v/5A7bse3p9DM+OqN0sy+rH+t2zk q/7hUpq2j1dKRTvaIVz8 =kpWi -----END PGP SIGNATURE-----