Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE request: Digest::SHA double free when using load subroutine
From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 16 Jan 2013 07:49:59 +0100

Hi Kurt and Florian

On Tue, Jan 15, 2013 at 10:37:59PM -0700, Kurt Seifried wrote:
Hash: SHA1

On 01/15/2013 12:37 PM, Florian Weimer wrote:
* Kurt Seifried:

I'm not clear, how would an attacker exploit this? They'd need to
be able to specify the file that gets hashed, and the file would
have to be not present and would thus trigger the crash? Are
there any real world examples of an affected application? (web

My hunch is that this is just a bug, not a security issue.

I'll leave it for now, if anyone comes up with a security impact/etc.
let us know! (I bet this never happens, ah well =).

Thanks for your feedback on this.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]