This is the mail archive of the glibc-bugs@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

[Bug libc/17905] catopen() Multiple unbounded stack allocations (CVE-2015-8779)


https://sourceware.org/bugzilla/show_bug.cgi?id=17905

--- Comment #3 from cvs-commit at gcc dot gnu.org <cvs-commit at gcc dot gnu.org> ---
This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "GNU C Library master sources".

The branch, release/2.21/master has been updated
       via  163437ec37ea32e82469de9b6cbed0d7209551c1 (commit)
       via  f676ce661cc319c0a984b93e4879aa717fb6240b (commit)
       via  907cc11c576a21ea6df5f5ad0a2b1dc3b55dd553 (commit)
      from  dbcaca73cb0a19698ea1b424087e8997a9b7c3c4 (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=163437ec37ea32e82469de9b6cbed0d7209551c1

commit 163437ec37ea32e82469de9b6cbed0d7209551c1
Author: Paul Pluzhnikov <ppluzhnikov@google.com>
Date:   Sat Sep 26 13:27:48 2015 -0700

    Fix BZ #18985 -- out of range data to strftime() causes a segfault

    (cherry picked from commit d36c75fc0d44deec29635dd239b0fbd206ca49b7)

https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=f676ce661cc319c0a984b93e4879aa717fb6240b

commit f676ce661cc319c0a984b93e4879aa717fb6240b
Author: Paul Pluzhnikov <ppluzhnikov@google.com>
Date:   Sat Aug 8 15:54:40 2015 -0700

    Fix trailing space.

    (cherry picked from commit 7565d2a862683a3c26ffb1f32351b8c5ab9f7b31)

https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=907cc11c576a21ea6df5f5ad0a2b1dc3b55dd553

commit 907cc11c576a21ea6df5f5ad0a2b1dc3b55dd553
Author: Paul Pluzhnikov <ppluzhnikov@google.com>
Date:   Sat Aug 8 15:53:03 2015 -0700

    Fix BZ #17905

    (cherry picked from commit 0f58539030e436449f79189b6edab17d7479796e)

-----------------------------------------------------------------------

Summary of changes:
 ChangeLog              |   16 ++++++++++++++
 NEWS                   |    2 +-
 catgets/Makefile       |    9 +++++++-
 catgets/catgets.c      |   19 +++++++++++------
 catgets/open_catalog.c |   23 ++++++++++++--------
 catgets/tst-catgets.c  |   31 ++++++++++++++++++++++++++++
 time/strftime_l.c      |   20 ++++++++++++------
 time/tst-strftime.c    |   52 +++++++++++++++++++++++++++++++++++++++++++++++-
 8 files changed, 146 insertions(+), 26 deletions(-)

-- 
You are receiving this mail because:
You are on the CC list for the bug.

Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]