oss-sec mailing list archives

Re: GHOST gethostbyname() heap overflow in glibc (CVE-2015-0235)


From: Paul Pluzhnikov <ppluzhnikov () gmail com>
Date: Thu, 29 Jan 2015 08:00:48 -0800

On Thu, Jan 29, 2015 at 4:09 AM, Hanno Böck <hanno () hboeck de> wrote:

And yes: I'd like people to cry alarm every time they see a buffer
overflow in glibc or any other core lib.

What is the appropriate forum to cry alarm on?

We are not a distro, and (AFAICT) are not on any of the closed lists.
But maybe we should be.

Thanks,
-- 
Paul Pluzhnikov


Current thread: