Fedora alert FEDORA-2016-fd26f713e7 (libksba)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 23 Update: libksba-1.3.4-1.fc23 | |
Date: | Mon, 16 May 2016 22:29:01 +0000 (UTC) | |
Message-ID: | <20160516222901.7E01C6079D17@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-fd26f713e7 2016-05-16 16:05:11.553638 -------------------------------------------------------------------------------- Name : libksba Product : Fedora 23 Version : 1.3.4 Release : 1.fc23 URL : http://www.gnupg.org/ Summary : CMS and X.509 library Description : KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. -------------------------------------------------------------------------------- Update Information: Security fix for minor security issues CVE-2016-4574, CVE-2016-4579. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1335396 - CVE-2016-4579 libksba: Out-of-bounds read in _ksba_ber_parse_tl https://bugzilla.redhat.com/show_bug.cgi?id=1335396 [ 2 ] Bug #1334831 - CVE-2016-4574 libksba: Incomplete fix for CVE-2016-4356 https://bugzilla.redhat.com/show_bug.cgi?id=1334831 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libksba' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org http://lists.fedoraproject.org/admin/lists/package-announ...