Re: J.C. Cleaver 2015-01-22 <user-4199642a17cb@xymon.invalid>
On Thu, January 22, 2015 8:14 am, Christoph Berg wrote:
This might even deserve a CVE number, but as it's a seccgi, it's
not widely exposed.
This is fixed in (unreleased) 4.3.18, via
https://sourceforge.net/p/xymon/code/7483.
Originally reported
http://lists.xymon.com/pipermail/xymon/2014-August/040003.html
Oh, ok. I thought about checking svn, but then didn't. Thanks for the
pointer!
Still, this is a pretty bad buffer overflow, so a new release should
be made soonish. We'll push this patch into the 4.3.17 in Debian Jessie.
Christoph
--
user-92157dbc91bf@xymon.invalid | http://www.df7cb.de/