MGASA-2017-0158
Dashboard / Vulnerabilities / MGASA-2017-0158
Summary: Updated libnl3 packages fix security vulnerability
Details: An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process (CVE-2017-0386). An integer overflow vulnerability was found in nlmsg_reserve() triggered by crafted @len argument resulting into reserving too few bytes (CVE-2017-0553).
References: https://advisories.mageia.org/MGASA-2017-0158.html, https://bugs.mageia.org/show_bug.cgi?id=20168, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JR5R2FSPYCLDAHTXQC2LKY74N5YW2PQQ/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/KIHASXRQO2YTQPKVP4VGIB2XHPANG6YX/
Affected packages
Package
Name: libnl3
Purl: pkg:rpm/mageia/libnl3?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
