Welcome! Log In Create A New Profile

Advanced

null pointer dereference vulnerability in 0.1.0-0.8.13.

Posted by Igor Sysoev 
All files from this thread

File NameFile Size Posted byDate 
patch.null.pointer.txt.bin430 bytesopen | downloadIgor Sysoev10/26/2009Read message
null pointer dereference vulnerability in 0.1.0-0.8.13.
October 26, 2009 02:52PM
A patch to fix null pointer dereference vulnerability in 0.1.0-0.8.13.
The patch is not required for versions 0.8.15+, 0.7.62+, 0.6.39+, 0.5.38+.


--
Igor Sysoev
http://sysoev.ru/en/
Attachments:
open | download - patch.null.pointer.txt.bin (430 bytes)
On Monday 26 October 2009 19:46:58 Igor Sysoev wrote:
> A patch to fix null pointer dereference vulnerability in 0.1.0-0.8.13.
> The patch is not required for versions 0.8.15+, 0.7.62+, 0.6.39+, 0.5.38+.

Hello Igor,

Can you confirm that it's related to this vulnerability?

http://www.securityfocus.com/bid/36839

Thanks !

--
Pior Bastida
pior@pbastida.net
Re: null pointer dereference vulnerability in 0.1.0-0.8.13.
October 30, 2009 12:38PM
On Fri, Oct 30, 2009 at 05:22:41PM +0100, Pior Bastida wrote:

> On Monday 26 October 2009 19:46:58 Igor Sysoev wrote:
> > A patch to fix null pointer dereference vulnerability in 0.1.0-0.8.13.
> > The patch is not required for versions 0.8.15+, 0.7.62+, 0.6.39+, 0.5.38+.
>
> Hello Igor,
>
> Can you confirm that it's related to this vulnerability?
>
> http://www.securityfocus.com/bid/36839

Yes. However, it's not a buffer overflow as stated there.
The published exploit causes always a null pointer dereference only
and you can not execute arbitrary code as stated there.


--
Igor Sysoev
http://sysoev.ru/en/
On Friday 30 October 2009 17:32:48 Igor Sysoev wrote:
> On Fri, Oct 30, 2009 at 05:22:41PM +0100, Pior Bastida wrote:
> > On Monday 26 October 2009 19:46:58 Igor Sysoev wrote:
> > > A patch to fix null pointer dereference vulnerability in 0.1.0-0.8.13.
> > > The patch is not required for versions 0.8.15+, 0.7.62+, 0.6.39+,
> > > 0.5.38+.
> >
> > Hello Igor,
> >
> > Can you confirm that it's related to this vulnerability?
> >
> > http://www.securityfocus.com/bid/36839
>
> Yes. However, it's not a buffer overflow as stated there.
> The published exploit causes always a null pointer dereference only
> and you can not execute arbitrary code as stated there.

Thank you !

--
Pior Bastida
pior@pbastida.net
Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 77
Record Number of Users: 10 on August 27, 2010
Record Number of Guests: 177 on August 21, 2010
Powered by nginx    Powered by FreeBSD    PHP Powered    Powered by MySQL