lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20170731092230.v6eqj55lsvpnrnz7@tunkki> Date: Mon, 31 Jul 2017 12:22:30 +0300 From: Henri Salo <henri@...v.fi> To: "qflb.wu" <qflb.wu@...ppsecurity.com.cn> Cc: fulldisclosure@...lists.org Subject: Re: [FD] libao memory corruption vulnerability On Mon, Jul 31, 2017 at 02:26:36PM +0800, qflb.wu wrote: > libao memory corruption vulnerability > > ./mpg321 libao_1.2.0_memory_corruption.mp3 > > CVE-2017-11548 Did you also test this with the latest version of the library? Issues like these might not be fixed by backporting in distros. Did you report this to the upstream? -- Henri Salo _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists