MGASA-2014-0188
Dashboard / Vulnerabilities / MGASA-2014-0188
MGASA-2014-0188
Summary: Updated systemd packages fix a buffer overflow
Details: A stack-based buffer overflow was found in systemd-ask-password, a utility used to query a system password or passphrase from the user, using a question message specified on the command line. A local user could this flaw to crash the binary or even execute arbitrary code with the permissions of the user running the program. The systemd packages shipped with Mageia 3 and 4 have been updated to address this vulnerability. Additionally, the Mageia 4 packages include various other general stability and performance fixed deemed appropriate for the stable updates.
References: https://advisories.mageia.org/MGASA-2014-0188.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-April/131370.html, https://bugs.mageia.org/show_bug.cgi?id=13219
Affected packages
Package
Name: systemd
Purl: pkg:rpm/mageia/systemd?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
