Lucene search

K
mageiaGentoo FoundationMGASA-2014-0442
HistoryNov 12, 2014 - 12:56 p.m.

Updated apt packages fix security vulnerability

2014-11-1212:56:47
Gentoo Foundation
advisories.mageia.org
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

76.4%

The Google Security Team discovered a buffer overflow vulnerability in the HTTP transport code in apt-get. An attacker able to man-in-the-middle a HTTP request to an apt repository can trigger the buffer overflow, leading to a crash of the “http” apt method binary, or potentially to arbitrary code execution (CVE-2014-6273). Also fixed is parsing of Mageia package index “synthesis” files with lines longer than 64k characters. This is necessary for upgrading to the “cauldron” development distro that will become Mageia 5. Note however that upgrading from Mageia 3 to Mageia 5 will not be supported.

OSVersionArchitecturePackageVersionFilename
Mageia3noarchapt< 0.5.15lorg3.94-9.2apt-0.5.15lorg3.94-9.2.mga3
Mageia4noarchapt< 0.5.15lorg3.94-11.2apt-0.5.15lorg3.94-11.2.mga4

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.005

Percentile

76.4%