{"id":"MGASA-2015-0185","summary":"Updated polarssl & hiawatha packages fix security vulnerabilities","details":"Updated hiawatha package fixes security vulnerabilities:\n\nThe hiawatha package included a bundled copy of PolarSSL 1.3.2, which was\nvulnerable to several security issues that had already been fixed in the\nsystem polarssl package.  These issues were CVE-2014-4911, CVE-2014-8627,\nCVE-2014-8628, and CVE-2015-1182, which were fixed in MGASA-2014-0315,\nMGASA-2014-0481, and MGASA-2015-0055.\n\nThe polarssl package has been adjusted so that hiawatha can use it, and\nhiawatha has been rebuilt to use the updated system polarssl, fixing these\nissues.\n","modified":"2026-04-16T04:28:10.018989Z","published":"2015-05-05T13:36:50Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0185.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15391"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0315.html"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2014-0481.html"},{"type":"ADVISORY","url":"http://advisories.mageia.org/MGASA-2015-0055.html"}],"affected":[{"package":{"name":"polarssl","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/polarssl?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.9-1.2.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0185.json"}},{"package":{"name":"hiawatha","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/hiawatha?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3-1.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0185.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}