mirror of
https://sourceware.org/git/glibc.git
synced 2024-11-30 05:03:46 +08:00
6cdc442142
This commit adds "advisories" entries for the above three CVEs.
16 lines
706 B
Plaintext
16 lines
706 B
Plaintext
syslog: Heap buffer overflow in __vsyslog_internal
|
|
|
|
__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER
|
|
containing a long program name failed to update the required buffer
|
|
size, leading to the allocation and overflow of a too-small buffer on
|
|
the heap.
|
|
|
|
CVE-Id: CVE-2023-6246
|
|
Public-Date: 2024-01-30
|
|
Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37)
|
|
Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39)
|
|
Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42)
|
|
Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57)
|
|
Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16)
|
|
Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126)
|