oss-sec mailing list archives

Re: CVE request: out-of-bounds memory access flaw in unrtf


From: Hanno Böck <hanno () hboeck de>
Date: Wed, 3 Dec 2014 15:48:49 +0100

On Wed, 03 Dec 2014 07:37:54 -0700
"Vincent Danen" <vdanen () redhat com> wrote:

https://bugzilla.redhat.com/show_bug.cgi?id=1170233

You mixed up Michal and me :-)

But appart from that: It's really not a single issue. I just fuzzed one
and reported it to check whether there is any reaction. But you easily
get dozends if you run afl on it.

If you want to fix unrtf there's more to it than that. Basically you'd
have to fork it and take over development. Same is true for a whole
bunch of other tools (catdoc, antiword, latex2rtf, ...)


-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: _bin
Description: OpenPGP digital signature


Current thread: