oss-sec mailing list archives
CVE request: thttpd: Denial of Service (App. crash, local)
From: Matthias Weckbecker <mweckbecker () suse de>
Date: Wed, 12 Dec 2012 11:57:16 +0100
Hi Kurt, Steve, vendors, ..., I think I have never posted it to oss-sec. glibc's crypt() can return NULL under some circumstances which causes thttpd to crash while dereferencing: https://bugzilla.novell.com/show_bug.cgi?id=783165 Maybe you want to assign a CVE. Matthias -- Matthias Weckbecker, Senior Security Engineer, SUSE Security Team SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany Tel: +49-911-74053-0; http://suse.com/ SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg)
Current thread:
- CVE request: thttpd: Denial of Service (App. crash, local) Matthias Weckbecker (Dec 12)
- Re: CVE request: thttpd: Denial of Service (App. crash, local) Henri Salo (Dec 12)
- Re: CVE request: thttpd: Denial of Service (App. crash, local) Kurt Seifried (Dec 14)