oss-sec mailing list archives
Re: CVE Assignment (gnustep)
From: Josh Bressers <bressers () redhat com>
Date: Fri, 7 May 2010 14:42:38 -0400 (EDT)
----- "Dan Rosenberg" <dan.j.rosenberg () gmail com> wrote:
Note that there's a second bug in there - a potentially exploitable integer overflow leading to heap overflow when reading a file (or socket) with a very large number of lines, causing several malloc() calls to underallocate space. This should probably receive a second CVE. http://article.gmane.org/gmane.comp.lib.gnustep.bugs/12379
Ahh, I missed that one. I see it now, thanks.
Use CVE-2010-1620 for the integer overflow.
Thanks.
--
JB
Current thread:
- CVE Assignment (gnustep) Josh Bressers (May 07)
- Re: CVE Assignment (gnustep) Dan Rosenberg (May 07)
- Re: CVE Assignment (gnustep) Josh Bressers (May 07)
- Re: CVE Assignment (gnustep) Dan Rosenberg (May 07)
