Re: CVE-2008-1391 - Multiple BSD Platforms "strfmon()" Function

看板FB_security作者時間18年前 (2008/04/07 06:20), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
Simon L. Nielsen wrote: > On 2008.04.06 12:47:11 -0700, stheg olloydson wrote: > >> According to the information at mitre.org, both 6.x and 7.0 are >> vulnerable. I see in NetBSD's CVS log for >> src/lib/libc/stdlib/strfmon.c, they have patched this on March >> 27. > > Note that the change in NetBSD is possibly incomplete to fix the > issue. I'm not sure what the final conclusion was on that. > The final conclusion was a subsequent commit on the 27th: http://archive.netbsd.se/?ml=netbsd-source-changes&a=2008-03&m=6750722 http://archive.netbsd.se/?ml=netbsd-source-changes&a=2008-03&m=6846592 We're still in the process of getting the changes pulled up. adrian. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #17-Kos00 (FB_security)
文章代碼(AID): #17-Kos00 (FB_security)