Jump to content

Advisories MDKSA-2006:140: Updated ncompress packages fix vulnerability


paul
 Share

Recommended Posts

Tavis Ormandy, of the Google Security Team, discovered that ncompress,

when uncompressing data, performed no bounds checking, which could

allow a specially crafted datastream to underflow a .bss buffer with

attacker controlled data.

 

Updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...