MGASA-2023-0265 - Updated libtommath packages fix security vulnerability

Publication date: 24 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0265.html
Type: security
Affected Mageia releases: 8, 9
CVE: CVE-2023-36328

libtomath is vulnerable to an Integer Overflow vulnerability that could
allow attackers to execute arbitrary code and cause a denial of service
(DoS). (CVE-2023-36328)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32247
- https://github.com/libtom/libtommath/pull/546
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36328

SRPMS:
- 9/core/libtommath-1.2.1-1.mga9
- 8/core/libtommath-1.2.1-1.mga8

Mageia 2023-0265: libtommath security update

libtomath is vulnerable to an Integer Overflow vulnerability that could allow attackers to execute arbitrary code and cause a denial of service (DoS)

Summary

libtomath is vulnerable to an Integer Overflow vulnerability that could allow attackers to execute arbitrary code and cause a denial of service (DoS). (CVE-2023-36328)

References

- https://bugs.mageia.org/show_bug.cgi?id=32247

- https://github.com/libtom/libtommath/pull/546

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36328

Resolution

MGASA-2023-0265 - Updated libtommath packages fix security vulnerability

SRPMS

- 9/core/libtommath-1.2.1-1.mga9

- 8/core/libtommath-1.2.1-1.mga8

Severity
Publication date: 24 Sep 2023
URL: https://advisories.mageia.org/MGASA-2023-0265.html
Type: security
CVE: CVE-2023-36328

Related News