Mageia alert MGASA-2017-0028 (389-ds-base)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2017-0028: Updated 389-ds-base packages fix security vulnerability | |
Date: | Fri, 27 Jan 2017 21:31:26 +0100 | |
Message-ID: | <20170127203126.3BDC79F7E7@duvel.mageia.org> |
MGASA-2017-0028 - Updated 389-ds-base packages fix security vulnerability Publication date: 27 Jan 2017 URL: http://advisories.mageia.org/MGASA-2017-0028.html Type: security Affected Mageia releases: 5 CVE: CVE-2017-2591 Description: The "attribute uniqueness" plugin did not properly NULL-terminate an array when building up its configuration if a so called 'old-style' configuration was being used. An attacker, authenticated, but possibly also unauthenticated, could possibly force the plugin to read beyond allocated memory and trigger a segfault. The crash could also possibly be triggered accidentally (CVE-2017-2591). References: - https://bugs.mageia.org/show_bug.cgi?id=20138 - http://www.openwall.com/lists/oss-security/2017/01/18/5 - https://fedorahosted.org/389/ticket/48986 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2591 SRPMS: - 5/core/389-ds-base-1.3.4.14-1.1.mga5