MGASA-2017-0225
Dashboard / Vulnerabilities / MGASA-2017-0225
Summary: Updated libmtp and libgphoto packages fix security vulnerabilities
Details: An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp and libgphoto allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable (CVE-2017-9831). An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp and libgphoto allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable (CVE-2017-9832).
References: https://advisories.mageia.org/MGASA-2017-0225.html, https://bugs.mageia.org/show_bug.cgi?id=21177, https://lists.fedoraproject.org/archives/list/[email protected]/thread/LTQ4RARXHHXXKCHPXONGT7HSMAQXNAVM/
Affected packages
Package
Name: libmtp
Purl: pkg:rpm/mageia/libmtp?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
