MGASA-2014-0553
Dashboard / Vulnerabilities / MGASA-2014-0553
Summary: Updated erlang packages fix security vulnerabilities
Details: Updated erlang packages fixes security vulnerability: An FTP command injection flaw was found in Erlang's FTP module. Several functions in the FTP module do not properly sanitize the input before passing it into a control socket. A local attacker can use this flaw to execute arbitrary FTP commands on a system that uses this module (CVE-2014-1693). This update also disables SSLv3 by default to mitigate the POODLE issue.
References: https://advisories.mageia.org/MGASA-2014-0553.html, https://bugs.mageia.org/show_bug.cgi?id=14715, https://lists.fedoraproject.org/pipermail/package-announce/2014-December/145017.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-December/146184.html
Affected packages
Package
Name: erlang
Purl: pkg:rpm/mageia/erlang?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
