Fwd: security vulnerability in File

Christos Zoulas christos at zoulas.com
Tue Feb 25 10:32:37 EST 2003


On Feb 24,  7:42pm, ian at darwinsys.com (Ian Darwin) wrote:
-- Subject: Fwd: security vulnerability in File

| I've received what looks like a legitimate report of a security
| buffer overflow-type problem in file up to 3.39. Can somebody
| who is more familiar with the ELF module please check into this
| fairly quickly and get back do David Endler before he goes public
| with this?
| 
| Thanks
| Ian

Actually the program headers can be taken advantage to the same way.
I have a more complete patch.

christos



More information about the File mailing list