|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0310 (libksba)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0310: Updated libksba packages fix security vulnerability
Date:  Wed, 21 Sep 2016 22:38:55 +0200
Message-ID:  <20160921203855.79CD49F776@duvel.mageia.org>

MGASA-2016-0310 - Updated libksba packages fix security vulnerability Publication date: 21 Sep 2016 URL: http://advisories.mageia.org/MGASA-2016-0310.html Type: security Affected Mageia releases: 5 Description: It was found that an unproportionate amount of memory is allocated when parsing crafted certificates in libskba, which may lead to DoS. Moreover in libksba 1.3.4, allocated memory is uninitialized and could potentially contain sensitive data left in freed memory block. References: - https://bugs.mageia.org/show_bug.cgi?id=19288 - http://openwall.com/lists/oss-security/2016/08/20/3 - http://openwall.com/lists/oss-security/2016/08/22/7 - https://lists.fedoraproject.org/archives/list/package-ann... SRPMS: - 5/core/libksba-1.3.5-1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds