|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0084 (xdelta3)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0084: Updated xdelta3 packages fix CVE-2014-9765
Date:  Wed, 2 Mar 2016 19:29:16 +0100
Message-ID:  <20160302182916.4DE469F698@duvel.mageia.org>

MGASA-2016-0084 - Updated xdelta3 packages fix CVE-2014-9765 Publication date: 02 Mar 2016 URL: http://advisories.mageia.org/MGASA-2016-0084.html Type: security Affected Mageia releases: 5 CVE: CVE-2014-9765 Description: Updated xdelta3 package fixes security vulnerability: Stepan Golosunov discovered that xdelta3, a diff utility which works with binary files, is affected by a buffer overflow vulnerability within the main_get_appheader function, which may lead to the execution of arbitrary code (CVE-2014-9765). References: - https://bugs.mageia.org/show_bug.cgi?id=17713 - https://www.debian.org/security/2016/dsa-3484 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9765 SRPMS: - 5/core/xdelta3-3.0.0-5.1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds