|
|
| |
|
| |
gc: code execution
| Package(s): | gc |
CVE #(s): | CVE-2012-2673
|
| Created: | June 28, 2012 |
Updated: | October 3, 2012 |
| Description: |
From the Red Hat bug report:
A security flaw was found in the way malloc() and calloc() routines implementation of gc, a Boehm-Demers-Weiser conservative garbage collector, performed parameters sanitization, when allocating memory. If an application using the gc collector was missing application-level malloc() and calloc() routines parameters validity checks, a remote attacker could provide a specially-crafted application-specific input file that, when opened in that application would lead to application crash or, potentially, arbitrary code execution with the privileges of the user running the application. |
| Alerts: |
|
( Log in to post comments)
|
|
|