oss-sec mailing list archives

Re: CVE Assignment (gnustep)


From: Josh Bressers <bressers () redhat com>
Date: Fri, 7 May 2010 14:42:38 -0400 (EDT)


----- "Dan Rosenberg" <dan.j.rosenberg () gmail com> wrote:

Note that there's a second bug in there - a potentially exploitable
integer overflow leading to heap overflow when reading a file (or
socket) with a very large number of lines, causing several malloc()
calls to underallocate space.  This should probably receive a second
CVE.

http://article.gmane.org/gmane.comp.lib.gnustep.bugs/12379


Ahh, I missed that one. I see it now, thanks.

Use CVE-2010-1620 for the integer overflow.

Thanks.

-- 
    JB


Current thread: