Date: Thu, 25 Aug 2011 08:18:47 +0200 From: Tomas Hoger <thoger@...hat.com> To: oss-security@...ts.openwall.com Subject: Re: CVE request: libqt4: two memory issues On Wed, 24 Aug 2011 15:49:17 -0400 (EDT) Josh Bressers wrote: > > A) buffer overflow (looks only like an off-by-one from a very quick > > look) > > http://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c > > Use CVE-2011-3193 for this. > > I couldn't find this code in Harfbuzz-ng or pango. Has someone looked > into this further? In both harfbuzz and pango git, history of the file ends with "Remove old code!" removal: http://git.gnome.org/browse/pango/log/pango/opentype/harfbuzz-gpos.c http://cgit.freedesktop.org/harfbuzz/log/src/harfbuzz-gpos.c -- Tomas Hoger / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ