|
Message-ID: <485A8B62.3050503@gentoo.org>
Date: Thu, 19 Jun 2008 18:37:54 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: oss-security@...ts.openwall.com
CC: coley@...re.org
Subject: CVE request: php 5.2.6 ext/imap buffer overflows
Heya,
php-5.2.6 uses old c-client API calls in ext/imap, which do not have any
bound checkings, as such it seems to be vulnerable to buffer overflow
problems. Can we get a CVE id for this issue please?
References:
http://bugs.php.net/bug.php?id=42862
http://bugs.php.net/bug.php?id=40925
https://bugs.gentoo.org/show_bug.cgi?id=221969
--
Christian Hoffmann
Download attachment "signature.asc" of type "application/pgp-signature" (261 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.