The package musl before version 1.1.17-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201710-28 ========================================= Severity: Critical Date : 2017-10-21 CVE-ID : CVE-2017-15650 Package : musl Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-457 Summary ====== The package musl before version 1.1.17-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.1.17-1. # pacman -Syu "musl> =1.1.17-1" The problem has been fixed upstream in version 1.1.17. Workaround ========= Using a local, trusted DNS resolver mitigates the issue. Description ========== A stack-based buffer overflow has been found in the DNS response parsing code of musl libc
Get the latest Linux and open source security news straight to your inbox.