oss-sec mailing list archives

Re: CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input


From: Florian Weimer <fw () deneb enyo de>
Date: Mon, 19 Apr 2010 17:19:18 +0200

* Matthias Andree:

Type:         malloc() Buffer overrun with printable characters

Is this the right summary?  It sounds like a heap buffer overflow, but
based on the description, I think it's just an infinite loop
allocating lots of memory.


Current thread: