MGASA-2014-0319
Dashboard / Vulnerabilities / MGASA-2014-0319
Summary: Updated readline packages fix security vulnerability
Details: Steve Kemp discovered the _rl_tropen() function in readline insecurely handled a temporary file. This could allow a local attacker to perform symbolic link attacks (CVE-2014-2524). Also, upstream patches have been added to fix an infinite loop in vi input mode, and to fix an issue with slowness when pasting text.
References: https://advisories.mageia.org/MGASA-2014-0319.html, https://bugs.mageia.org/show_bug.cgi?id=13512, https://lists.fedoraproject.org/pipermail/package-announce/2014-July/135686.html
Affected packages
Package
Name: readline
Purl: pkg:rpm/mageia/readline?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -6.2-7.1.mga3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
