LWN.net Logo

Mageia alert MGASA-2013-0206 (php-radius)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0206: Updated php-radius packages fix CVE-2013-2220
Date:  Tue, 9 Jul 2013 20:33:40 +0200
Message-ID:  <20130709183340.3688040C1A@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0206 - Updated php-radius packages fix CVE-2013-2220 Publication date: 09 Jul 2013 URL: http://advisories.mageia.org/MGASA-2013-0206.html Type: security Affected Mageia releases: 2, 3 CVE: CVE-2013-2220 Description: Updated php-radius package fixes security vulnerability: Fix a security issue in radius_get_vendor_attr() by enforcing checks of the VSA length field against the buffer size (CVE-2013-2220). References: - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2220 - http://pecl.php.net/package-changelog.php?package=radius&... - http://www.mandriva.com/en/support/security/advisories/ad... - https://bugs.mageia.org/show_bug.cgi?id=10642 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2220 SRPMS: - 3/core/php-radius-1.2.7-1.mga3 - 2/core/php-radius-1.2.7-1.mga2


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds