[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: OpenBSD 4.1 - Heap overflow vulnerabillity
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Re: OpenBSD 4.1 - Heap overflow vulnerabillity
- From: Steve Shockley <steve.shockley@xxxxxxxxxxxx>
- Date: Tue, 28 Aug 2007 14:14:22 -0400
acheddamiman@xxxxxxxxx wrote:
The command "file" is vulnerable to heap overflow.
Solution:
Patch the kernel source with:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.1/common/009_file.patch
By AchedDamiman
This is CVE-2007-1536, discovered by Jean-Sebastien Guay-Leroux.
Patches are also available for OpenBSD 4.0:
http://openbsd.org/errata40.html#015_file