[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Fri, 28 Mar 2008 01:16:23 +0100
From: Nico Golde <oss-security+ml@...lde.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVEs for zzuf crashers?
Hi Hanno,
* Hanno Böck <hanno@...eck.de> [2008-03-28 00:26]:
> Sam Hovecar has created zzuf more than a year ago and posted a bunch of
> samples crashing various multimedia and other apps:
> http://sam.zoy.org/blog/2007-01-16-exposing-file-parsing-vulnerabilities
>
> I've done some re-testing about a year later:
> http://hboeck.de/archives/578-How-long-does-it-take-to-fix-a-crash-bug.html
>
> Some are still unfixed, I recently opened some upstream bug reports:
[...]
Since a crash itself in a non-service appliction is not necessary
a security issue I think we should check them in detail
before assigning CVE ids for them (does not mean they are
non-issues though).
Kind regards
Nico
--
Nico Golde - http://www.ngolde.de - nion@...ber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux