oss-sec mailing list archives
Re: Nagios format string issues
From: Josh Bressers <bressers () redhat com>
Date: Wed, 6 Oct 2010 10:46:54 -0400 (EDT)
----- "Oden Eriksson" <oeriksson () mandriva com> wrote:
We have a whole bunch of similar patches in Mandriva, just fetch the cooker source rpm packages and do something like: rpm -qlp *.src,rpm | grep format It would be a major task to push that to the upstream projects. Just checked the ones I fixed (in 2008/2009): $ rpm -qlp /SRPMS/contrib/release/*.rpm /SRPMS/main/release/*.rpm | grep format_not_a_string_literal_and_no_format_arguments | wc -l 106 So, at least 106 new CVE assignments there.
It's probably not 106. Just becuase something isn't using format arguments doesn't mean it's a security flaw. Some subset of these probably could be considered security flaws though. Does anyone know any tricks for wading through this many patches? It would be wise to see about initiating a process to get these upstream. Thanks. -- JB
Current thread:
- Nagios format string issues Florian Weimer (Oct 05)
- Re: Nagios format string issues Oden Eriksson (Oct 06)
- <Possible follow-ups>
- Re: Nagios format string issues Josh Bressers (Oct 06)
- Re: Nagios format string issues Steven M. Christey (Oct 06)
- Re: Nagios format string issues Oden Eriksson (Oct 06)
- Re: Nagios format string issues Tomas Hoger (Oct 07)
- Re: Nagios format string issues Oden Eriksson (Oct 12)