Bug#895653: corosync: CVE-2018-1084: Integer overflow in exec/totemcrypto.c:authenticate_nss_2_3() function

2018-04-14 Thread Ferenc Wágner
Unfortunately the Alioth list migration delayed this mail long enough to let me do the security upload without closing this bug in the changelog. You may want to fill that in during the DSA workflow (if possible). -- Regards, Feri

Bug#895653: corosync: CVE-2018-1084: Integer overflow in exec/totemcrypto.c:authenticate_nss_2_3() function

2018-04-13 Thread Salvatore Bonaccorso
Source: corosync Version: 2.4.2-3 Severity: grave Tags: security upstream Hi, The following vulnerability was published for corosync, tracking bug for the BTS, although we know Ferenc is already aware. CVE-2018-1084[0]: | corosync before version 2.4.4 is vulnerable to an integer overflow in | ex