|
Message-Id: <20140926040205.B6FCA72E1E5@smtpvbsrv1.mitre.org> Date: Fri, 26 Sep 2014 00:02:05 -0400 (EDT) From: cve-assign@...re.org To: huzaifas@...hat.com, marc.deslauriers@...onical.com Cc: cve-assign@...re.org, oss-security@...ts.openwall.com Subject: Re: Fwd: Non-upstream patches for bash -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > From: Marc Deslauriers > Could we please get two CVE numbers assigned for the two OOB memory issues? > From: Florian Weimer > The redir_stack issue is this: > -static REDIRECT *redir_stack[10]; This is apparently an error in handling here documents that can be fixed by not using the above array size. Use CVE-2014-7186. > The word_lineno issue is this > case FOR: > - if (word_top < MAX_CASE_NEST) > + if (word_top + 1 < MAX_CASE_NEST) This is apparently an off-by-one error in the processing of deeply nested for loops. Use CVE-2014-7187. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJUJORKAAoJEKllVAevmvmsX7YH/jmzRQO8Uyc5R4M3KP/yomee 7f+WOjD5j7aLuaRATnFZD9NuuchP9jofpJfkV5nUw2QuT5+1Hb+WW7k8tQHB4+w+ P0RZLIMAPJDe5hJGtUIOFwBfvii4lSDw1G9ij6/1ObIGETPJmO8ioT4jTP98hRvf F3I+RiVKjytMQhZKwvuK4gsT2b8pHcP0iAKTiSiV/U9qME4lIZkBee8a3pFSaYKw RlHohbPy6ucBwSRtYaTzKBNM1g6XXMrVWa09YvL8hdtJM1w2hrD+Bxm/PZnER5Sr VCpQqJVOZtKeykNQ95v8xIitwhEcwwy3AGXfg4urvqYAJ5EnyJKV1u2Ky97Ds5A= =imiZ -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.