LWN.net Logo

Mageia alert MGASA-2012-0205 (dropbear)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0205: dropbear-2012.55-1.mga1 (1/core)
Date:  Sun, 12 Aug 2012 19:27:12 +0200
Message-ID:  <20120812172712.GA20943@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0205 Date: August 12th, 2012 Affected releases: 1 Description: Updated dropbear package fixes security vulnerability: Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency" (CVE-2012-0920). Updated Packages: dropbear-2012.55-1.mga1 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0920 http://www.debian.org/security/2012/dsa-2456 https://bugs.mageia.org/show_bug.cgi?id=5611 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds