MGASA-2014-0362

Source
https://advisories.mageia.org/MGASA-2014-0362.html
Import Source
https://advisories.mageia.org/MGASA-2014-0362.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0362
Related
Published
2014-09-01T10:44:17Z
Modified
2014-09-01T10:34:17Z
Summary
Updated distcc packages fix CVE-2014-4607
Details

Updated distcc packages fix security vulnerability:

An integer overflow in liblzo before 2.07 allows attackers to cause a denial of service or possibly code execution in applications using performing LZO decompression on a compressed payload from the attacker (CVE-2014-4607).

The distcc package is built with a bundled copy of minilzo, which is a part of liblzo containing the vulnerable code.

References
Credits

Affected packages

Mageia:4 / distcc

Package

Name
distcc
Purl
pkg:rpm/mageia/distcc?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2rc1-5.1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / distcc

Package

Name
distcc
Purl
pkg:rpm/mageia/distcc?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2rc1-3.1.mga3

Ecosystem specific

{
    "section": "core"
}