MGASA-2014-0460
Dashboard / Vulnerabilities / MGASA-2014-0460
Summary: Updated boinc-client packages fix security vulnerability
Details: Multiple stack overflow flaws were found in the way the XML parser of boinc-client, a Berkeley Open Infrastructure for Network Computing (BOINC) client for distributed computing, performed processing of certain XML files. A rogue BOINC server could provide a specially-crafted XML file that, when processed would lead to boinc-client executable crash (CVE-2013-2298). Issues preventing the boinc-client service from working immediately after installation have been fixed as well.
References: https://advisories.mageia.org/MGASA-2014-0460.html, https://bugs.mageia.org/show_bug.cgi?id=12129, https://lists.fedoraproject.org/pipermail/package-announce/2013-December/125125.html, https://bugs.mageia.org/show_bug.cgi?id=9108, https://bugs.mageia.org/show_bug.cgi?id=9109
Affected packages
Package
Name: boinc-client
Purl: pkg:rpm/mageia/boinc-client?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
