Mageia alert MGASA-2017-0327 (botan)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2017-0327: Updated botan packages fix security vulnerability | |
| Date: | Sun, 3 Sep 2017 16:32:12 +0200 | |
| Message-ID: | <20170903143212.92E9B9F872@duvel.mageia.org> |
MGASA-2017-0327 - Updated botan packages fix security vulnerability Publication date: 03 Sep 2017 URL: http://advisories.mageia.org/MGASA-2017-0327.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-2801 Description: Aleksandar Nikolic discovered that an error in the x509 parser of the Botan crypto library could result in an out-of-bounds memory read, resulting in denial of service or an information leak if processing a malformed certificate (CVE-2017-2801). References: - https://bugs.mageia.org/show_bug.cgi?id=21528 - https://botan.randombit.net/security.html - https://www.debian.org/security/2017/dsa-3939 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2801 SRPMS: - 6/core/botan-1.10.14-5.1.mga6
