ALAS-2015-500


Amazon Linux AMI Security Advisory: ALAS-2015-500
Advisory Release Date: 2015-04-01 17:02 Pacific
Severity: Low
References: CVE-2014-3564 

Issue Overview:

Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."


Affected Packages:

gpgme


Issue Correction:
Run yum update gpgme to update your system.

New Packages:
i686:
    gpgme-devel-1.4.3-5.15.amzn1.i686
    gpgme-1.4.3-5.15.amzn1.i686
    gpgme-debuginfo-1.4.3-5.15.amzn1.i686

src:
    gpgme-1.4.3-5.15.amzn1.src

x86_64:
    gpgme-devel-1.4.3-5.15.amzn1.x86_64
    gpgme-debuginfo-1.4.3-5.15.amzn1.x86_64
    gpgme-1.4.3-5.15.amzn1.x86_64