ALAS-2016-712


Amazon Linux 1 Security Advisory: ALAS-2016-712
Advisory Release Date: 2016-06-02 18:19 Pacific
Advisory Updated Date: 2016-06-03 19:56 Pacific
Severity: Medium

Issue Overview:

The following security-related issues were resolved:

Incomplete fix for CVE-2016-4356 (CVE-2016-4574)
Out-of-bounds read in _ksba_ber_parse_tl (CVE-2016-4579)


Affected Packages:

libksba


Issue Correction:
Run yum update libksba to update your system.

New Packages:
i686:
    libksba-1.3.4-1.8.amzn1.i686
    libksba-devel-1.3.4-1.8.amzn1.i686
    libksba-debuginfo-1.3.4-1.8.amzn1.i686

src:
    libksba-1.3.4-1.8.amzn1.src

x86_64:
    libksba-devel-1.3.4-1.8.amzn1.x86_64
    libksba-debuginfo-1.3.4-1.8.amzn1.x86_64
    libksba-1.3.4-1.8.amzn1.x86_64