MGASA-2019-0327

Source
https://advisories.mageia.org/MGASA-2019-0327.html
Import Source
https://advisories.mageia.org/MGASA-2019-0327.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0327
Related
Published
2019-11-14T17:33:29Z
Modified
2019-11-14T16:40:46Z
Summary
Updated libapreq2 packages fix security vulnerability
Details

Updated libapreq2 packages fix security vulnerability:

Max Kellermann reported a NULL pointer dereference flaw in libapreq2, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested "multipart" body is processed (CVE-2019-12412).

References
Credits

Affected packages

Mageia:7 / libapreq2

Package

Name
libapreq2
Purl
pkg:rpm/mageia/libapreq2?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.130.0-28.1.mga7

Ecosystem specific

{
    "section": "core"
}