MGASA-2016-0256

Source
https://advisories.mageia.org/MGASA-2016-0256.html
Import Source
https://advisories.mageia.org/MGASA-2016-0256.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0256
Related
Published
2016-07-14T20:33:59Z
Modified
2016-07-14T20:26:56Z
Summary
Updated util-linux packages fix security vulnerability
Details

The util-linux libblkid is vulnerable to a Denial of Service attack during MSDOS partition table parsing, in the extended partition boot record (EBR). If the next EBR starts at relative offset 0, parsedosextended() will loop until running out of memory. An attacker could install a specially crafted MSDOS partition table in a storage device and trick a user into using it. This library is used, among others, by systemd-udevd daemon (CVE-2016-5011).

References
Credits

Affected packages

Mageia:5 / util-linux

Package

Name
util-linux
Purl
pkg:rpm/mageia/util-linux?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.25.2-3.4.mga5

Ecosystem specific

{
    "section": "core"
}