OpenSSL, GnuGP, Ghostscript, and Perl Updates for Debian 7 Extended LTS

Published by

4 security updates has been released for Debian GUN/Linux 7 Extended LTS:
ELA-4-1 openssl security update
Possible DoS by a malicious server that sends a very large prime value to the client during TLS handshake.

ELA-5-1 gnupg security update
Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

ELA-6-1 ghostscript security update
A vulnerability was discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may lead to the potential information disclosure about files for which read permissions are not available.

ELA-7-1 perl security update
Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive.
 OpenSSL, GnuGP, Ghostscript, and Perl Updates for Debian 7 Extended LTS