Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20100426181408.18181340@redhat.com>
Date: Mon, 26 Apr 2010 18:14:08 +0200
From: Tomas Hoger <thoger@...hat.com>
To: OSS Security <oss-security@...ts.openwall.com>
Cc: ppisar@...hat.com
Subject: WordNet wn format string issue

Hi!

Petr Pisar discovered a format string bug in wordnet while doing review
of wordnet packages in Fedora / RHEL:

  https://bugzilla.redhat.com/show_bug.cgi?id=585206
  https://bugs.gentoo.org/show_bug.cgi?id=317265

We're not treating this as security issue (no good attack vector,
fortify source mitigation) and fixing it as a regular bug.  Though as
the issue can be triggered in a similar way as CVE-2008-2149, and some
vendors fixed that one as security, bringing this to attention if
anyone wants to use a different approach.

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.