Updated libmms packages fix CVE-2014-2892
Publication date: 23 Apr 2014Modification date: 23 Apr 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-2892
Description
Updated libmms packages fix security vulnerability: The libmms library before 0.6.4 is vulnerable to a buffer overflow in get_answer() in src/mmsh.c. It may be triggered via an overly long line of a MMSH (MMS over HTTP) server response, effectively overflowing the buffer which has a static size (CVE-2014-2892).
References
SRPMS
4/core
- libmms-0.6.2-4.1.mga4
3/core
- libmms-0.6.2-3.1.mga3