USN-4828-1: librelp vulnerability
15 March 2021
librelp could be made to run programs as an administrator.
Releases
Packages
- librelp - Reliable Event Logging Protocol (RELP) library
Details
It was discovered that librelp did not properly manage x509 certificates,
leading to a stack-based buffer overflow. A remote attacker could possibly
use this issue to execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
librelp0
-
1.2.14-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
librelp0
-
1.2.9-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-3612-1: librelp, librelp-dev, librelp0