Bug 18951 - qpid-proton-java new security issue CVE-2016-4467
Summary: qpid-proton-java new security issue CVE-2016-4467
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Pascal Terjan
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-15 13:31 CEST by David Walser
Modified: 2017-05-01 22:34 CEST (History)
2 users (show)

See Also:
Source RPM: qpid-proton-java-0.12.0-1.mga6.src.rpm
CVE: CVE-2016-4467
Status comment:


Attachments

Description David Walser 2016-07-15 13:31:57 CEST
Upstream has issued an advisory today (July 15):
http://openwall.com/lists/oss-security/2016/07/15/3

The issue is fixed in 0.13.1.

Mageia 5 is not affected.
David Walser 2016-07-15 13:32:09 CEST

CC: (none) => geiger.david68210, mageia

Nicolas Lécureuil 2017-05-01 22:29:41 CEST

CVE: (none) => CVE-2016-4467

Comment 1 Nicolas Lécureuil 2017-05-01 22:34:47 CEST
Fixed in cauldron

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.