MGASA-2014-0460

Source
https://advisories.mageia.org/MGASA-2014-0460.html
Import Source
https://advisories.mageia.org/MGASA-2014-0460.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0460
Upstream
Published
2014-11-21T12:44:16Z
Modified
2026-04-16T06:26:31.622408980Z
Summary
Updated boinc-client packages fix security vulnerability
Details

Multiple stack overflow flaws were found in the way the XML parser of boinc-client, a Berkeley Open Infrastructure for Network Computing (BOINC) client for distributed computing, performed processing of certain XML files. A rogue BOINC server could provide a specially-crafted XML file that, when processed would lead to boinc-client executable crash (CVE-2013-2298).

Issues preventing the boinc-client service from working immediately after installation have been fixed as well.

References
Credits

Affected packages

Mageia:3 / boinc-client

Package

Name
boinc-client
Purl
pkg:rpm/mageia/boinc-client?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.42-1.2.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0460.json"

Mageia:4 / boinc-client

Package

Name
boinc-client
Purl
pkg:rpm/mageia/boinc-client?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.2.42-1.2.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0460.json"