MGASA-2014-0442
Dashboard / Vulnerabilities / MGASA-2014-0442
Summary: Updated apt packages fix security vulnerability
Details: The Google Security Team discovered a buffer overflow vulnerability in the HTTP transport code in apt-get. An attacker able to man-in-the-middle a HTTP request to an apt repository can trigger the buffer overflow, leading to a crash of the "http" apt method binary, or potentially to arbitrary code execution (CVE-2014-6273). Also fixed is parsing of Mageia package index "synthesis" files with lines longer than 64k characters. This is necessary for upgrading to the "cauldron" development distro that will become Mageia 5. Note however that upgrading from Mageia 3 to Mageia 5 will not be supported.
References: https://advisories.mageia.org/MGASA-2014-0442.html, https://bugs.mageia.org/show_bug.cgi?id=14112, http://www.ubuntu.com/usn/usn-2353-1/
Affected packages
Package
Name: apt
Purl: pkg:rpm/mageia/apt?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
