oss-sec mailing list archives
Re: CVE-2019-5544 openslp 1.2.1, 2.0.0 heap overflow vulnerability
From: Riccardo Schirone <rschiron () redhat com>
Date: Tue, 10 Dec 2019 11:25:23 +0100
On 12/06, VMware Security Response Center wrote:
openslp has a heap overflow vulnerability that when exploited may result in memory corruption and a crash of slpd or in remote code execution. CVE-2019-5544 has been assigned to this issue. Below you may find: - a copy of the affected code with comments indicating the problem. - patches for openslp versions 1.2.1 and 2.0.0
Are those fixes commited anywhere? I could not find them on GitHub.
VMware would like to thank the 360Vulcan team working with the 2019 Tianfu Cup Pwn Contest for reporting this issue to us. VMware Security Response Center
Thanks, -- Riccardo Schirone Red Hat -- Product Security Email: rschiron () redhat com PGP-Key ID: CF96E110
Attachment:
signature.asc
Description:
Current thread:
- CVE-2019-5544 openslp 1.2.1, 2.0.0 heap overflow vulnerability VMware Security Response Center (Dec 05)
- Re: CVE-2019-5544 openslp 1.2.1, 2.0.0 heap overflow vulnerability Riccardo Schirone (Dec 10)
- Re: CVE-2019-5544 openslp 1.2.1, 2.0.0 heap overflow vulnerability VMware Security Response Center (Dec 11)
- Re: CVE-2019-5544 openslp 1.2.1, 2.0.0 heap overflow vulnerability Riccardo Schirone (Dec 10)