Advisories ยป MGASA-2014-0190

Updated libmms packages fix CVE-2014-2892

Publication date: 23 Apr 2014
Modification date: 23 Apr 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-2892

Description

Updated libmms packages fix security vulnerability:

The libmms library before 0.6.4 is vulnerable to a buffer overflow in
get_answer() in src/mmsh.c.  It may be triggered via an overly long line
of a MMSH (MMS over HTTP) server response, effectively overflowing the
buffer which has a static size (CVE-2014-2892).
                

References

SRPMS

4/core

3/core