Slackware64-13.37 ChangeLog (2018-04-27)
Fri Apr 27 03:58:48 UTC 2018
Packages
Upgraded
- patches/packages/openvpn-2.4.6-x86_64-1_slack13.37.txz
This is a security update fixing a potential double-free() in Interactive
Service. This usually only leads to a process crash (DoS by an unprivileged
local account) but since it could possibly lead to memory corruption if
happening while multiple other threads are active at the same time,
CVE-2018-9336 has been assigned to acknowledge this risk.
For more information, see:
https://github.com/OpenVPN/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9336
(* Security fix *)