Re: Old cscope buffer overflow

From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 6 May 2009 11:49:14 -0400 (EDT)

On Tue, 5 May 2009, Tomas Hoger wrote:

If you're preparing cscope updates for CVE-2009-0148 and you may still
be shipping packages based on 15.5, you may want to have a look at:


Steve, as the first public report for this is from 2006:


I believe 2006 CVE id is needed here.

We recently updated CVE-2009-0148 for overflows in cscope before 15.7a.
Is this the same issue, or do we need a different one?

This seems to be distinct from CVE-2006-4262 as well...

Multiple buffer overflows in cscope 15.5 and earlier allow
user-assisted attackers to cause a denial of service (crash) and
possibly execute arbitrary code via multiple vectors including (1) a
long pathname that is not properly handled during file list parsing,
(2) long pathnames that result from path variable expansion such as
tilde expansion for the HOME environment variable, and (3) a long -f
(aka reffile) command line argument.

Multiple buffer overflows in Cscope before 15.7a allow remote
attackers to execute arbitrary code via (1) long pathnames, (2) long
source-code strings, and other vectors.

