Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <5A8CF0F7-6FD9-4534-884A-A8AE71777270@apache.org>
Date: Thu, 4 Oct 2018 22:28:16 -0400
From: Velmurugan Periasamy <vel@...che.org>
To: security <security@...che.org>,
 oss-security@...ts.openwall.com
Cc: private@...ger.apache.org,
 dev@...ger.apache.org,
 user@...ger.apache.org
Subject: CVE update - fixed in Apache Ranger 1.2.0

Hello:

Please find below details on CVE fixed in Ranger 1.2.0 release. Release details can be found at https://cwiki.apache.org/confluence/display/RANGER/1.2.0+Release+-+Apache+Ranger

————————————————————————————————————————————————————————————————————————————————————————————————————————
CVE-2018-11778: Apache Ranger Stack based buffer overflow
Severity: Critical
Vendor: The Apache Software Foundation
Versions Affected: Apache Ranger versions prior to 1.2.0
Users affected: Unix Authentication Service users 
Description: Apache Ranger UnixAuthenticationService should properly handle user input to avoid Stack-based buffer overflow.
Fix detail: UnixAuthenticationService was updated to correctly handle user input.
Mitigation: Users should upgrade to 1.2.0 or later version of Apache Ranger with the fix.
Credit: Alexander Klink.
————————————————————————————————————————————————————————————————————————————————————————————————————————

Thank you,
Velmurugan Periasamy

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.