oss-sec mailing list archives

Re: CVE request: fetchmail 4.6.3...6.3.16 DoS in -v -v mode in multibyte locales on invalid input


From: "Matthias Andree" <matthias.andree () gmx de>
Date: Tue, 20 Apr 2010 10:08:41 +0200

Am 19.04.2010, 17:19 Uhr, schrieb Florian Weimer:

* Matthias Andree:

Type:           malloc() Buffer overrun with printable characters

Is this the right summary?  It sounds like a heap buffer overflow, but
based on the description, I think it's just an infinite loop
allocating lots of memory.

That's why it's a "draft". Thanks.

--
Matthias Andree


Current thread: