oss-sec mailing list archives

Re: GHOST gethostbyname() heap overflow in glibc (CVE-2015-0235)


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Tue, 27 Jan 2015 09:21:32 -0800

I find it... profoundly disappointing... that we get to learn about
0-days via PR agency leaks (or that external PR agencies get to know
about 0-days before the rest of the world - hey, sounds like a juicy
target).

That said, the advisory makes up for it...

/mz


Current thread: