MGASA-2016-0310
Dashboard / Vulnerabilities / MGASA-2016-0310
MGASA-2016-0310
Summary: Updated libksba packages fix security vulnerability
Details: It was found that an unproportionate amount of memory is allocated when parsing crafted certificates in libskba, which may lead to DoS. Moreover in libksba 1.3.4, allocated memory is uninitialized and could potentially contain sensitive data left in freed memory block.
References: https://advisories.mageia.org/MGASA-2016-0310.html, https://bugs.mageia.org/show_bug.cgi?id=19288, http://openwall.com/lists/oss-security/2016/08/20/3, http://openwall.com/lists/oss-security/2016/08/22/7, https://lists.fedoraproject.org/archives/list/[email protected]/thread/KUORSGVTYHQQKX2AYN7ASGUMPKFCV3HJ/
Affected packages
Package
Name: libksba
Purl: pkg:rpm/mageia/libksba?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
