http://www.mandriva.com/en/
______________________________
Package : graphviz
Date : April 1, 2015
Affected: Business Server 2.0
______________________________
Problem Description:
Updated graphviz packages fix security vulnerability:
Format string vulnerability in the yyerror function in
lib/cgraph/scan.l in Graphviz allows remote attackers to have
unspecified impact via format string specifiers in unknown vector,
which are not properly handled in an error string (CVE-2014-9157).
Additionally the gtkglarea2 and gtkglext packages were missing and
was required for graphviz to build, these packages are also being
provided with this advisory.
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 2/X86_64:
9bafda1801998f26c9de8715a5b4f2
69d0e786218156bda6ce3ae386ce7e
970a121e1ad3396d744b729ccf0ae8
2defc0a9c1b055d4c8aeddbb30d292
517a130b8db8d596acc58c67889bbb
b622bf72651687ff76529d5c794160
e697fb1ccf65f78abed726a76baa8b
3c736ee01ead6eca0ee34dd4144c5b
ad99471421e44c95c0e88520eabf63
2a6b3ed54c0bbf4ce7657a7295baf5
affcfec0d5c47c4d7f40b6433afb9e
b3d9803dc5be936b4977fcd07fd8c2
281a1f3ecbcc2936040a964884a022
ce23e49e1b648587fe6b7ea091b1dc
ada3a4bc05689b2e99ffedb93adf33
a53d3cefebcaaccd64733ecd44b5ac
acfac83dc5cfe4e6dd36d8d9383342
908183bccda9074dd050d2db15ec3a
5310a33b0b1366631f627314264eee
ed47d6081c39dfa6ca44aabb09c6b4
6c1cbbd3de624c944dc68d353d9eda
c59bd68ec8a4cbc245c931cc066f2b
493dd7182d4bfc70d0844ecd5fdd8c
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą