Debian Security Advisory

DLA-892-1 libnl3 -- LTS security update

Date Reported:
10 Apr 2017
Affected Packages:
libnl3
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-0553.
More information:

It was discovered that there was an integer overflow in libnl3, a library for dealing with netlink sockets.

A missing check in nlmsg_reserve() could have allowed a malicious application to execute arbitrary code within the context of the WiFi service.

For Debian 7 Wheezy, this issue has been fixed in libnl3 version 3.2.7-4+deb7u1.

We recommend that you upgrade your libnl3 packages.