MGASA-2017-0201
Dashboard / Vulnerabilities / MGASA-2017-0201
Summary: Updated libffi packages fix security vulnerability
Details: libffi, a library used to call code written in one language from code written in a different language, was enforcing an executable stack on the i386 architecture. While this might not be considered a vulnerability by itself, this could be leveraged when exploiting other vulnerabilities, such as the "stack clash" class of vulnerabilities discovered by Qualys Research Labs.
References: https://advisories.mageia.org/MGASA-2017-0201.html, https://bugs.mageia.org/show_bug.cgi?id=21122, https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt, https://github.com/libffi/libffi/commit/978c9540154d320525488db1b7049277122f736d
Affected packages
Package
Name: libffi
Purl: pkg:rpm/mageia/libffi?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
