Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 19 May 2013 13:06:49 +0300
From: Henri Salo <>
Subject: Re: plone, rrdtool, zenoss bugs

On Thu, Apr 18, 2013 at 02:05:42PM +0200, Thomas Pollet wrote:
> Also,
> the rrdtool python module crashes on format string exploit
> $ python -c "import rrdtool
> rrdtool.graph('/tmp/out.png','-f','%n%n')"
> Segmentation fault
> this module is used by zenoss to create graphs (zenoss users are able to
> pass arguments to rrdtool).

Tested Debian wheezy packages:

python-rrdtool 1.4.7-2
python2.7 2.7.3-6

Backtrace attached. Might affect other software too.
Debian bug:

Henri Salo

View attachment "python-rrdtool-bt.txt" of type "text/plain" (4247 bytes)

Download attachment "signature.asc" of type "application/pgp-signature" (199 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.