MGASA-2015-0185

Source
https://advisories.mageia.org/MGASA-2015-0185.html
Import Source
https://advisories.mageia.org/MGASA-2015-0185.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0185
Published
2015-05-05T13:36:50Z
Modified
2026-04-16T04:28:10.018989Z
Summary
Updated polarssl & hiawatha packages fix security vulnerabilities
Details

Updated hiawatha package fixes security vulnerabilities:

The hiawatha package included a bundled copy of PolarSSL 1.3.2, which was vulnerable to several security issues that had already been fixed in the system polarssl package. These issues were CVE-2014-4911, CVE-2014-8627, CVE-2014-8628, and CVE-2015-1182, which were fixed in MGASA-2014-0315, MGASA-2014-0481, and MGASA-2015-0055.

The polarssl package has been adjusted so that hiawatha can use it, and hiawatha has been rebuilt to use the updated system polarssl, fixing these issues.

References
Credits

Affected packages

Mageia:4 / polarssl

Package

Name
polarssl
Purl
pkg:rpm/mageia/polarssl?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.9-1.2.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0185.json"

Mageia:4 / hiawatha

Package

Name
hiawatha
Purl
pkg:rpm/mageia/hiawatha?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3-1.1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0185.json"