Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-9332 http://linux.oracle.com/errata/ELSA-2025-9332.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: mpfr-3.1.1-4.0.1.el7.i686.rpm mpfr-3.1.1-4.0.1.el7.x86_64.rpm mpfr-devel-3.1.1-4.0.1.el7.i686.rpm mpfr-devel-3.1.1-4.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/mpfr-3.1.1-4.0.1.el7.src.rpm Related CVEs: CVE-2014-9474 Description of changes: [3.1.1-4.0.1] - Fixes buffer overflow in mpfr_strtofr (CVE-2014-9474) [Orabug: 38103811] _______________________________________________ El-errata mailing list
Multiple buffer overflows in MPFR might lead to a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: MPFR: Denial of Service Date: March 09, 2009 Bugs: #260968 ID: 200903-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple buffer overflows in MPFR might lead to a Denial of Service. Background ========= MPFR is a library for multiple-precision floating-point computations with exact rounding. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/mpfr < 2.4.1 > = 2.4.1 Description ========== Multiple buffer overflows have been reported in the mpfr_snprintf() and mpfr_vsnprintf() functions. Impact ===== A remote user could exploit the vulnerability to cause a Denial of Service in an application using MPFR via unknown vectors. Workaround ========= There is no known workaround at this time. Resolution ========= All MPRF users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/mpfr-2.4.1" References ========= [ 1 ] CVE-2009-0757 https://www.cve.org/CVERecord?id=CVE-2009-0757 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is ofutmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.