LWN.net Logo

pl: code execution

Package(s):pl CVE #(s):CVE-2012-6090 CVE-2012-6089
Created:January 15, 2013 Updated:January 16, 2013
Description: From the CVE entries:

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename. (CVE-2012-6090)

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename. (CVE-2012-6089)

Alerts:
Fedora FEDORA-2013-0178 2013-01-15
Fedora FEDORA-2013-0211 2013-01-15
Fedora FEDORA-2013-0225 2013-01-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds