lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 29 Mar 2016 04:43:24 +0000 From: Salvatore Bonaccorso <carnil@...ian.org> To: bugtraq@...urityfocus.com Subject: [SECURITY] [DSA 3533-1] openvswitch security update -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3533-1 security@...ian.org https://www.debian.org/security/ Salvatore Bonaccorso March 29, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openvswitch CVE ID : CVE-2016-2074 Kashyap Thimmaraju and Bhargava Shastry discovered a remotely triggerable buffer overflow vulnerability in openvswitch, a production quality, multilayer virtual switch implementation. Specially crafted MPLS packets could overflow the buffer reserved for MPLS labels in an OVS internal data structure. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially, execution of arbitrary code. For the stable distribution (jessie), this problem has been fixed in version 2.3.0+git20140819-3+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 2.3.0+git20140819-4. We recommend that you upgrade your openvswitch packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@...ts.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJW+gc+AAoJEAVMuPMTQ89EebsP/1Yn7B3eB+Uq80rhUpOeC//C 2epUQlzGJBtJZAt6XvSFQtQIllLHJqtiu4CHog4tvurmKqOBHsSvX8ZtzHC7vRyo 6Bj49aPr/8v/DHertec0ETEnTWVEtz+6LOVBsyelWLQRDwqVwxzr68xNNX1C1/Ya CuhK2IhFtIr807241QZkHW+8Lb+iw9W0oCIdVjF79oe7p+PGZkkOVF8AAmoBheVj +8yHmRhrX9ALjeEuRriaZP0OyMSPEMxn5T+UDaCUTneyO3HGTB7x3CxQTDeDLhr/ mwQz6lad6mSGj+vOcY1WIhnKt7xPmB6LpxOKUTYOWR/IF9+7Fw8YDnpvNz4cxaXK rmPsJ1qqqAp6MlNo9laS+gQyS3T3lOxSDaRo5MLIXxxJH4JLS4bM0fofjbL9CE/X iCLFlexLZmjG9Wg84LOYxNijcSST7ae/BwU+6s66pDplw4wfYQrxnlgJXHj7Mufj 2vLcpqU2Kx0PuKhunwNEzkZM9TiE7xfII+4SsMAbYJ9hopN0vlyys96v7u9MMdK8 XtSQu/mKE9QCuVWDVmwGUMBN0SqSbPsydTPnUp3utOVrFFZUVnvHZKUG7LyEn/2d MUe85NQwd51KuCzzMkWHzi6QZTBXqwHj9ILbvkUNszEbX3E1Fz/d4rkvLISi63QS rDCkTON4f1BVwFNJAjfc =xNNL -----END PGP SIGNATURE-----
Powered by blists - more mailing lists