|
Message-Id: <5A8CF0F7-6FD9-4534-884A-A8AE71777270@apache.org> Date: Thu, 4 Oct 2018 22:28:16 -0400 From: Velmurugan Periasamy <vel@...che.org> To: security <security@...che.org>, oss-security@...ts.openwall.com Cc: private@...ger.apache.org, dev@...ger.apache.org, user@...ger.apache.org Subject: CVE update - fixed in Apache Ranger 1.2.0 Hello: Please find below details on CVE fixed in Ranger 1.2.0 release. Release details can be found at https://cwiki.apache.org/confluence/display/RANGER/1.2.0+Release+-+Apache+Ranger ———————————————————————————————————————————————————————————————————————————————————————————————————————— CVE-2018-11778: Apache Ranger Stack based buffer overflow Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Ranger versions prior to 1.2.0 Users affected: Unix Authentication Service users Description: Apache Ranger UnixAuthenticationService should properly handle user input to avoid Stack-based buffer overflow. Fix detail: UnixAuthenticationService was updated to correctly handle user input. Mitigation: Users should upgrade to 1.2.0 or later version of Apache Ranger with the fix. Credit: Alexander Klink. ———————————————————————————————————————————————————————————————————————————————————————————————————————— Thank you, Velmurugan Periasamy
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.