lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <322164720.20031219132548@Sniff-em.com> From: Thierry at Sniff-em.com (Thierry) Subject: Openware.org IE Fix - Warning According to Heise (http://www.heise.de/newsticker/data/dab-19.12.03-002/) The Openware.org IE fix introduces new flaws : - The buffer to copy URL's is limited to 256 bytes - Larger strings produce a buffer overflow, with possibility to overwrite the stack. BoF Test : http://www.heise.de/security/dienste/browsercheck/demos/ie/e5_18.shtml (at the bottom, link entitled "TEST DES PATCHES") -- Best regards, Thierry mailto:Thierry@...ff-em.com