LWN.net Logo

gc: code execution

Package(s):gc CVE #(s):CVE-2012-2673
Created:June 28, 2012 Updated:October 3, 2012
Description:

From the Red Hat bug report:

A security flaw was found in the way malloc() and calloc() routines implementation of gc, a Boehm-Demers-Weiser conservative garbage collector, performed parameters sanitization, when allocating memory. If an application using the gc collector was missing application-level malloc() and calloc() routines parameters validity checks, a remote attacker could provide a specially-crafted application-specific input file that, when opened in that application would lead to application crash or, potentially, arbitrary code execution with the privileges of the user running the application.

Alerts:
Fedora FEDORA-2012-9637 2012-06-28
Fedora FEDORA-2012-9556 2012-06-28
Ubuntu USN-1546-1 2012-08-28
Mageia MGASA-2012-0249 2012-08-30
Mandriva MDVSA-2012:158 2012-10-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds