Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Fri, 28 Mar 2008 00:07:22 +0100
From: Hanno Böck <hanno@...eck.de>
To: "Steven M. Christey" <coley@...us.mitre.org>,
  oss-security@...ts.openwall.com
Subject: CVEs for zzuf crashers?

Hi,

Sam Hovecar has created zzuf more than a year ago and posted a bunch of 
samples crashing various multimedia and other apps:
http://sam.zoy.org/blog/2007-01-16-exposing-file-parsing-vulnerabilities

I've done some re-testing about a year later:
http://hboeck.de/archives/578-How-long-does-it-take-to-fix-a-crash-bug.html

Some are still unfixed, I recently opened some upstream bug reports:
https://bugzilla.mozilla.org/show_bug.cgi?id=424333
also mentioned on http://www.securityfocus.com/bid/27243
http://bugs.xine-project.org/show_bug.cgi?id=74
http://bugzilla.mplayerhq.hu/show_bug.cgi?id=1043
(gstreamer not done yet, waiting for 0.10.18 to land in gentoo)

At least the firefox issue and the still open mediaplayer crashers could have 
their own CVE (if there aren't already ones for it).

-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux