Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <908504848.65321286376414054.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Wed, 6 Oct 2010 10:46:54 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: Nagios format string issues

----- "Oden Eriksson" <oeriksson@...driva.com> wrote:

> 
> We have a whole bunch of similar patches in Mandriva, just fetch the
> cooker source rpm packages and do something like:
> 
> rpm -qlp *.src,rpm | grep format
> 
> It would be a major task to push that to the upstream projects.
> 
> Just checked the ones I fixed (in 2008/2009):
> 
> $ rpm -qlp /SRPMS/contrib/release/*.rpm /SRPMS/main/release/*.rpm |
> grep 
> format_not_a_string_literal_and_no_format_arguments | wc -l
> 106
> 
> So, at least 106 new CVE assignments there.
> 
> 

It's probably not 106. Just becuase something isn't using format arguments
doesn't mean it's a security flaw. Some subset of these probably could be
considered security flaws though.

Does anyone know any tricks for wading through this many patches?

It would be wise to see about initiating a process to get these upstream.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.