[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Elixir - (bulletinjul2019)

ID: oval:org.secpod.oval:def:2104623Date: (C)2019-12-31   (M)2021-09-11
Class: PATCHFamily: unix




Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 0.19.

Platform:
Sun Solaris 11
Product:
developer/elixir/hex
Reference:
bulletinjul2019
CVE-2019-1000012
CVE    1
CVE-2019-1000012
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies