Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 19 Jun 2008 18:37:54 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: oss-security@...ts.openwall.com
CC: coley@...re.org
Subject: CVE request: php 5.2.6 ext/imap buffer overflows

Heya,

php-5.2.6 uses old c-client API calls in ext/imap, which do not have any 
bound checkings, as such it seems to be vulnerable to buffer overflow 
problems. Can we get a CVE id for this issue please?

References:
http://bugs.php.net/bug.php?id=42862
http://bugs.php.net/bug.php?id=40925
https://bugs.gentoo.org/show_bug.cgi?id=221969

-- 
Christian Hoffmann


Download attachment "signature.asc" of type "application/pgp-signature" (261 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.