SCIENTIFIC-LINUX-ERRATA Archives

August 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 21 Aug 2017 15:43:43 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (34 lines)
Synopsis:          Moderate: libtasn1 security, bug fix, and enhancement 
Advisory ID: SLSA-2017:1860-1
Issue Date: 2017-08-01
CVE Numbers: CVE-2015-2806
                   CVE-2015-3622
--

The following packages have been upgraded to a later upstream version:
libtasn1 (4.10).

Security Fix(es):

* A heap-based buffer overflow flaw was found in the way the libtasn1
library decoded certain DER-encoded inputs. A specially crafted DER-
encoded input could cause an application using libtasn1 to perform an
invalid read, causing the application to crash. (CVE-2015-3622)

* A stack-based buffer overflow was found in the way libtasn1 decoded
certain DER encoded data. An attacker could use this flaw to crash an
application using the libtasn1 library. (CVE-2015-2806)
--

SL7
  x86_64
    libtasn1-4.10-1.el7.i686.rpm
    libtasn1-4.10-1.el7.x86_64.rpm
    libtasn1-debuginfo-4.10-1.el7.i686.rpm
    libtasn1-debuginfo-4.10-1.el7.x86_64.rpm
    libtasn1-devel-4.10-1.el7.i686.rpm
    libtasn1-devel-4.10-1.el7.x86_64.rpm
    libtasn1-tools-4.10-1.el7.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2