Advisories ยป MGASA-2014-0315

Updated polarssl packages fix security vulnerability

Publication date: 05 Aug 2014
Modification date: 05 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-4911

Description

A flaw was discovered in PolarSSL, a lightweight crypto and SSL/TLS library,
which can be exploited by a remote unauthenticated attacker to mount a denial
of service against PolarSSL servers that offer GCM ciphersuites. Potentially
clients are affected too if a malicious server decides to execute the denial
of service attack against its clients (CVE-2014-4911).

The pdns package has been rebuilt against the updated polarssl library.
                

References

SRPMS

4/core

3/core