LWN.net Logo

Mageia alert MGASA-2012-0228 (usbmuxd)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0228: usbmuxd-1.0.7-1.2.mga1 (1/core), usbmuxd-1.0.7-2.2.mga2 (2/core)
Date:  Sat, 18 Aug 2012 20:06:28 +0200
Message-ID:  <20120818180628.GA12563@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0228 Date: August 18th, 2012 Affected releases: 1, 2 Description: Updated usbmuxd packages fix security vulnerability: It was discovered that usbmuxd did not correctly perform bounds checking when processing the SerialNumber field of USB devices. An attacker with physical access could use this to crash usbmuxd or potentially execute arbitrary code as the 'usbmux' user (CVE-2012-0065). Updated Packages: Mageia 1: usbmuxd-1.0.7-1.2.mga1 lib(64)usbmuxd1-1.0.7-1.2.mga1 lib(64)usbmuxd-devel-1.0.7-1.2.mga1 Mageia 2: usbmuxd-1.0.7-2.2.mga2 lib(64)usbmuxd1-1.0.7-2.2.mga2 lib(64)usbmuxd-devel-1.0.7-2.2.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0065 http://www.ubuntu.com/usn/usn-1354-1/ https://bugs.mageia.org/show_bug.cgi?id=6945 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds