LWN.net Logo

elinks: off-by-one buffer overflow

Package(s):elinks CVE #(s):CVE-2008-7224
Created:October 2, 2009 Updated:October 30, 2009
Description: From the Red Hat advisory: An off-by-one buffer overflow flaw was discovered in the way ELinks handled its internal cache of string representations for HTML special entities. A remote attacker could use this flaw to create a specially-crafted HTML file that would cause ELinks to crash or, possibly, execute arbitrary code when rendered.
Alerts:
Red Hat RHSA-2009:1471-01 2009-10-01
Ubuntu USN-851-1 2009-10-21
CentOS CESA-2009:1471 2009-10-06
CentOS CESA-2009:1471 2009-10-30
Debian DSA-1902-1 2009-10-05
Oracle ELSA-2013-0250 2013-02-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds