oss-sec mailing list archives

CVE Request -- libnids v1.24 -- Null pointer dereference


From: Jan Lieskovsky <jlieskov () redhat com>
Date: Thu, 01 Apr 2010 13:24:10 +0200

Hi Steve, vendors,

  libnids upstream has released latest, v1.24 version, addressing
one NULL pointer dereference:

  [1] http://libnids.sourceforge.net/
  [2] http://freefr.dl.sourceforge.net/project/libnids/libnids/1.24/libnids-1.24.releasenotes.txt

  "v1.24 Mar 14 2010
   - fixed another remotely triggerable NULL dereference in ip_fragment.c"

  [3] http://secunia.com/advisories/39225/

Could you allocate a CVE id for it?

Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


Current thread: