oss-sec mailing list archives

Re: Re: CVE request for icinga 1 byte \0 overflows


From: Agostino Sarubbo <ago () gentoo org>
Date: Thu, 13 Mar 2014 23:16:07 +0100

On Thursday 13 March 2014 15:30:31 cve-assign () mitre org wrote:
The icinga team silently fixed some single byte \0 overflows.

https://git.icinga.org/?p=icinga-core.git;a=commitdiff;h=73285093b71a5551a
bdaab0a042d3d6bae093b0d

(also the non public
https://dev.icinga.org/issues/5663
is referenced by commit above)

Use CVE-2014-2386.

We tracked a lot of similar issues:
https://bugs.gentoo.org/show_bug.cgi?id=fortify-source

-- 
Agostino Sarubbo
Gentoo Linux Developer


Current thread: