Advisories ยป MGASA-2017-0318

Updated libgxps packages fix security vulnerability

Publication date: 28 Aug 2017
Modification date: 28 Aug 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-11590

Description

There is a NULL pointer dereference in the caseless_hash function in
gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a denial
of service attack (CVE-2017-11590).
                

References

SRPMS

5/core

6/core