Bugzilla – Bug 977989
VUL-0: CVE-2016-4354: libksba: incorrect integer data type
Last modified: 2016-05-04 14:23:28 UTC
CVE-2016-4354 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4354 http://seclists.org/oss-sec/2016/q2/172 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4354.html
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2016-05-17. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62684
This issue seems to already have been fixed by 0002-Fix-integer-overflow-in-the-BER-decoder.patch present in all SUSE_SLE-10-SP3, SUSE_SLE-11, SUSE_SLE-12, openSUSE:13.2, openSUSE:Leap:42.1.