LWN.net Logo

libhx: arbitrary code execution

Package(s):libHX CVE #(s):CVE-2010-2947
Created:August 31, 2010 Updated:October 25, 2010
Description: From the Mandriva advisory:

Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.

Alerts:
Ubuntu USN-994-1 2010-09-29
Fedora FEDORA-2010-13155 2010-08-20
Fedora FEDORA-2010-13127 2010-08-20
Fedora FEDORA-2010-13155 2010-08-20
Fedora FEDORA-2010-13127 2010-08-20
Mandriva MDVSA-2010:165 2010-08-30
openSUSE openSUSE-SU-2010:0723-1 2010-10-14
SUSE SUSE-SR:2010:019 2010-10-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds