Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 26 Sep 2008 08:49:55 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE id request: faad2


----- "Steffen Joeris" <steffen.joeris@...lelinux.de> wrote:
> Hi
> 
> There is a heap overflow in faad2.
> Upstream announcement:
> http://www.audiocoding.com/
> 
> Gentoo Bugreport:
> http://bugs.gentoo.org/show_bug.cgi?id=238445
> 
> Debian Bugreport:
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499899
> 
> Upstream patch:
> http://www.audiocoding.com/patch/main_overflow.diff
> 
> Could I please get a CVE id for this?
> 

This has already been assigned CVE-2008-4201
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4201

It's not live on the MITRE site yet though.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ