apticron report [Sun, 30 Apr 2017 00:38:22 +0200]
========================================================================
apticron has detected that some packages need upgrading on:
quigon.federez.net
[ 160.228.155.65 ]
The following packages are currently pending an upgrade:
ghostscript 9.06~dfsg-2+deb8u5
libfreetype6 2.5.2-3+deb8u2
libgs9 9.06~dfsg-2+deb8u5
libgs9-common 9.06~dfsg-2+deb8u5
========================================================================
Package Details:
Lecture des fichiers de modifications (« changelog »)...
--- Modifications pour freetype (libfreetype6) ---
freetype (2.5.2-3+deb8u2) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
[ Moritz Mühlenhoff ]
* CVE-2016-10244 (Closes: #856971)
[ Salvatore Bonaccorso ]
* [psaux] Better protect `flex' handling (CVE-2017-8105) (Closes: #861220)
* t1_builder_close_contour: Add safety guard (CVE-2017-8287)
(Closes: #861308)
-- Salvatore Bonaccorso <carnil(a)debian.org> Thu, 27 Apr 2017 12:05:02 +0200
--- Modifications pour ghostscript (ghostscript libgs9 libgs9-common) ---
ghostscript (9.06~dfsg-2+deb8u5) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* Avoid divide by 0 in scan conversion code (CVE-2016-10219) (Closes:
#859666)
* fix crash with bad data supplied to makeimagedevice (CVE-2016-10220)
(Closes: #859694)
* use the correct param list enumerator (CVE-2017-5951) (Closes: #859696)
* Ensure a device has raster memory, before trying to read it
(CVE-2017-7207) (Closes: #858350)
* -dSAFER bypass and remote command execution via a "/OutputFile (%pipe%"
substring (CVE-2017-8291) (Closes: #861295)
-- Salvatore Bonaccorso <carnil(a)debian.org> Fri, 28 Apr 2017 10:32:58 +0200
========================================================================
You can perform the upgrade by issuing the command:
apt-get dist-upgrade
as root on quigon.federez.net
--
apticron