MGASA-2016-0181
Dashboard / Vulnerabilities / MGASA-2016-0181
Summary: Updated libksba packages fix security vulnerabilities
Details: Updated libksba packages fix security vulnerabilities: An out-of-bounds read access in _ksba_dn_to_str() in libksba 1.3.3, due to an incomplete fix for CVE-2016-4356, could result in denial of service (CVE-2016-4574). In liksba 1.3.3, the returned length of the object from _ksba_ber_parse_tl() (ti.length) was not always checked against the actual buffer length, thus leading to a read access after the end of the buffer, which could result in denial of service (CVE-2016-4579).
References: https://advisories.mageia.org/MGASA-2016-0181.html, https://bugs.mageia.org/show_bug.cgi?id=18437, http://openwall.com/lists/oss-security/2016/05/10/4, http://openwall.com/lists/oss-security/2016/05/11/10
Affected packages
Package
Name: libksba
Purl: pkg:rpm/mageia/libksba?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
