-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7561 2015-05-06 05:56:11 -------------------------------------------------------------------------------- Name : openslp Product : Fedora 20 Version : 1.2.1 Release : 22.fc20 URL : https://sourceforge.net/projects/openslp/ Summary : Open implementation of Service Location Protocol V2 Description : Service Location Protocol is an IETF standards track protocol that provides a framework to allow networking applications to discover the existence, location, and configuration of networked services in enterprise networks. OpenSLP is an open source implementation of the SLPv2 protocol as defined by RFC 2608 and RFC 2614. -------------------------------------------------------------------------------- Update Information: openslp: denial of service vulnerability (CVE-2010-3609) -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2015 Rex Dieter1.2.1-22 - openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS (CVE-2012-4428, #857242) * Mon May 4 2015 Rex Dieter 1.2.1-21 - openslp: denial of service vulnerability (CVE-2010-3609, #684294) -------------------------------------------------------------------------------- References: [ 1 ] Bug #684294 - CVE-2010-3609 openslp: denial of service vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=684294 [ 2 ] Bug #857242 - CVE-2012-4428 openslp: out-of-bounds read in SLPIntersectStringList() can cause DoS https://bugzilla.redhat.com/show_bug.cgi?id=857242 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openslp' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce