|
|
| |
|
| |
gmime22: arbitrary code execution
| Package(s): | gmime22 |
CVE #(s): | CVE-2010-0409
|
| Created: | February 5, 2010 |
Updated: | August 2, 2010 |
| Description: |
From the Red
Hat bugzilla:
Buffer overflow flaw was reported and fixed in the GMime library,
in the code part responsible for calculating the maximum number
of output bytes generated by an uuencode operation.
If a local user was tricked into running a specially-crafted
application, using the library, it could lead to denial of
service (supplied application crash) or, potentially, to arbitrary
code execution with the privileges of the user running that
application. |
| Alerts: |
|
( Log in to post comments)
|
|
|