Mageia alert MGASA-2015-0192 (erlang)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2015-0192: Updated erlang packages fix CVE-2015-2774 | |
Date: | Tue, 5 May 2015 18:38:39 +0200 | |
Message-ID: | <20150505163839.EB57A41C15@valstar.mageia.org> |
MGASA-2015-0192 - Updated erlang packages fix CVE-2015-2774 Publication date: 05 May 2015 URL: http://advisories.mageia.org/MGASA-2015-0192.html Type: security Affected Mageia releases: 4 CVE: CVE-2015-2774 Description: Updated erlang packages fix security vulnerability: Erlang's TLS-1.0 implementation failed to check padding bytes, leaving it vulnerable to an issue similar to POODLE (CVE-2015-2774). References: - https://bugs.mageia.org/show_bug.cgi?id=15580 - http://openwall.com/lists/oss-security/2015/03/27/9 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2774 SRPMS: - 4/core/erlang-R16B02-2.2.mga4