Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 11 High: libsilc Security Advisory for Buffer Overflow

fedora
Calendar Grey September 9, 2009
Dist Fedora Esm H88
The recent libsilc update in Fedora 11 resolves potential memory corruption and format discrepancies, bolstering both security and overall system reliability.

Summary

SILC Client Library libraries for clients to connect to SILC networks.

SILC (Secure Internet Live Conferencing) is a protocol which provides

secure conferencing services on the Internet over insecure channel.

ChangeLog:

* Fri Sep 4 2009 Stu Tomlinson 1.1.8-7

- Backport patch to fix stack corruption (CVE-2008-7160) (#521256)

* Fri Sep 4 2009 Stu Tomlinson 1.1.8-6

- Backport patch to fix additional string format vulnerabilities (#515648)

* Wed Aug 5 2009 Stu Tomlinson 1.1.8-5

- Backport patch to fix string format vulnerability (#515648)

* Sat Jul 25 2009 Fedora Release Engineering - 1.1.8-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

References:

[ 1 ] Bug #515648 - libsilc: format string vulnerability in client entry handling

https://bugzilla.redhat.com/show_bug.cgi?id=515648

[ 2 ] Bug #521256 - CVE-2008-7160 libsilc: stack corruption in SilcHttpServer on 64bit archs

https://bugzilla.redhat.com/show_bug.cgi?id=521256

This update can be installed with the "yum" update program. Use

su -c 'yum update libsilc' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Name: libsilc
Product: Fedora 11
Version: 1.1.8
Release: 7.fc11
URL:
Summary: SILC Client Library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here