Advisories ยป MGASA-2017-0028

Updated 389-ds-base packages fix security vulnerability

Publication date: 27 Jan 2017
Modification date: 27 Jan 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-2591

Description

The "attribute uniqueness" plugin did not properly NULL-terminate an
array when building up its configuration if a so called 'old-style'
configuration was being used. An attacker, authenticated, but possibly
also unauthenticated, could possibly force the plugin to read beyond
allocated memory and trigger a segfault. The crash could also possibly
be triggered accidentally (CVE-2017-2591).
                

References

SRPMS

5/core