Updated lha packages fix CVE-2016-1925
Publication date: 21 Apr 2016Modification date: 21 Apr 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-1925
Description
Updated lha package fixes security vulnerability: The lha command is vulnerable to a buffer overflow while processing level 0 and level 1 headers while extracting an archive (CVE-2016-1925).
References
SRPMS
5/core
- lha-1.14i-20160202.1.mga5