[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: Re: [oss-security] CVE request: libqt4: two memory issues
From: Tomas Hoger <thoger () redhat ! com>
Date: 2011-08-25 6:18:47
Message-ID: 20110825081847.0bee10d8 () redhat ! com
[Download RAW message or body]
On Wed, 24 Aug 2011 15:49:17 -0400 (EDT) Josh Bressers wrote:
> > A) buffer overflow (looks only like an off-by-one from a very quick
> > look)
> > http://qt.gitorious.org/qt/qt/commit/9ae6f2f9a57f0c3096d5785913e437953fa6775c
>
> Use CVE-2011-3193 for this.
>
> I couldn't find this code in Harfbuzz-ng or pango. Has someone looked
> into this further?
In both harfbuzz and pango git, history of the file ends with "Remove
old code!" removal:
http://git.gnome.org/browse/pango/log/pango/opentype/harfbuzz-gpos.c
http://cgit.freedesktop.org/harfbuzz/log/src/harfbuzz-gpos.c
--
Tomas Hoger / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic