Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 21 Sep 2010 15:33:01 +0400
From: Solar Designer <>
Subject: bzip2 CVE-2010-0405 integer overflow


Here's some analysis of this vulnerability and the changes in 1.0.6:

No conclusion on whether it is exploitable or not (and in what cases),
yet maybe this will save someone a few minutes.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ