Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian Stretch: DLA-903-2 High: Libfoo Buffer Overflow Risk

debian lts
Calendar Grey April 10, 2017
Dist Debian Esm H88
Buffer overflow identified in libnl3 on Debian Wheezy addressed in version 3.2.7-4+deb7u1. Update advised for protection.
It was discovered that there was an integer overflow in libnl3, a library for dealing with netlink sockets

Summary

A missing check in nlmsg_reserve() could have allowed a malicious application
to execute arbitrary code within the context of the WiFi service.

For Debian 7 "Wheezy", this issue has been fixed in libnl3 version
3.2.7-4+deb7u1.

We recommend that you upgrade your libnl3 packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
important
Lowest
Low
Medium
High
Critical

Package: libnl3
Version: 3.2.7-4+deb7u1
CVE ID: CVE-2017-0553
Debian Bug: #859948

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here