Advisories ยป MGASA-2015-0033

Updated elfutils packages fix CVE-2014-9447

Publication date: 20 Jan 2015
Modification date: 20 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9447

Description

Updated elfutils packages fix security vulnerability:

Directory traversal vulnerability in the read_long_names function in
libelf/elf_begin.c in elfutils allows remote attackers to write to arbitrary
files to the root directory via a / (slash) in a crafted archive, as
demonstrated using the ar program (CVE-2014-9447).
                

References

SRPMS

4/core