-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2014:166 http://www.mandriva.com/en/support/security/ _______________________________________________________________________ Package : serf Date : September 2, 2014 Affected: Business Server 1.0 _______________________________________________________________________ Problem Description: Updated serf packages fix security vulnerability: Ben Reser discovered that serf did not correctly handle SSL certificates with NUL bytes in the CommonName or SubjectAltNames fields. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications (CVE-2014-3504). _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3504 http://advisories.mageia.org/MGASA-2014-0353.html _______________________________________________________________________ Updated Packages: Mandriva Business Server 1/X86_64: 741d24f4b5c123e557ba7d83a62de3d1 mbs1/x86_64/lib64serf0-1.1.1-1.mbs1.x86_64.rpm f94ad58d4b5a4d7e132d27139727744d mbs1/x86_64/lib64serf-devel-1.1.1-1.mbs1.x86_64.rpm d696485167e8ed03bad287a0c75c9b2b mbs1/SRPMS/serf-1.1.1-1.mbs1.src.rpm _______________________________________________________________________ To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/en/support/security/advisories/ If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iD8DBQFUBcJEmqjQ0CJFipgRApJhAJ0VTsUUkj40pToB8Z1vghbW4nNKWgCfawVh kezYGvFQ0PZOahZcxUatIhc= =YLL5 -----END PGP SIGNATURE-----