Advisories ยป MGASA-2013-0318

Updated dropbear packages fix CVE-2013-4421

Publication date: 25 Oct 2013
Modification date: 25 Oct 2013
Type: security
Affected Mageia releases : 2 , 3
CVE: CVE-2013-4421 , CVE-2013-4434

Description

Updated dropbear package fixes security vulnerability:

Possible memory exhaustion denial of service due to the size of
decompressed payloads in dropbear before 2013.59 (CVE-2013-4421).

Inconsistent delays in authorization failures could be used to
disclose the existence of valid user accounts in dropbear before
2013.59 (CVE-2013-4434).
                

References

SRPMS

2/core

3/core