oss-sec mailing list archives
Re: CVE request: jhead
From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 15 Oct 2008 14:28:37 -0400 (EDT)
On Wed, 15 Oct 2008, Jamie Strandboge wrote:
CC'ing John, as he is who found the majority of the issues and coordinated with upstream.
So the jhead changelog only acknowledges "potential string overflows". John's comment in bug 271020 alludes to various other types of issues, but specifics are unknown. And there are some references to other overflows that may or may not have been fixed by upstream. So, we'd need multiple CVEs, but how many is unclear. 1 - long -cmd 2 - unsafe temp file creation 3 - "more unchecked buffers" and "unsafe buffer sized strcat's in ModifyDescriptComment" [this assumes that upstream only fixed issue 1) 4 - shell escapes Without knowing what exactly is being reported and fixed, it's pretty difficult to assign CVEs, especially with phrases like "more unchecked buffers" that could apply to anything. Use CVE-2008-4575 for the "long -cmd" ONLY - and whatever other overflows the upstream developer fixed. (That is, CVE-2008-4575 is focusing on what was fixed by upstream, not what's in the Ubuntu bug report). - Steve
Current thread:
- CVE request: jhead Jamie Strandboge (Oct 15)
- Re: CVE request: jhead Steven M. Christey (Oct 15)
- Re: CVE request: jhead John Dong (Oct 16)
- Re: CVE request: jhead Steven M. Christey (Oct 22)
- Re: CVE request: jhead Robert Buchholz (Nov 26)
- Re: CVE request: jhead John Dong (Oct 16)
- Re: CVE request: jhead Steven M. Christey (Oct 15)
- Re: CVE request: jhead Steven M. Christey (Oct 15)