[Bug binutils/22887] null pointer dereference in aout_32_swap_std_reloc_out

2018-04-26 Thread rsprudencio at gmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=22887

rsprudencio at gmail dot com changed:

   What|Removed |Added

 CC||rsprudencio at gmail dot com

--- Comment #7 from rsprudencio at gmail dot com ---
Previous versions like binutils-2.27 have similar (if not identical) code
without that fix, why only 2.30 was flagged as vulnerable? Could you elaborate?

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
bug-binutils mailing list
bug-binutils@gnu.org
https://lists.gnu.org/mailman/listinfo/bug-binutils


[Bug binutils/22887] null pointer dereference in aout_32_swap_std_reloc_out

2018-04-27 Thread rsprudencio at gmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=22887

--- Comment #9 from rsprudencio at gmail dot com ---
It was published with misleading information, giving the idea that only 2.30
was vulnerable, the matter here is clarity of information and which versions
were affected, I agree it is low priority, but NVD CVE page noting only 2.30
gives a really weak feedback to community which wishes to automate processes
like identifying vulnerable products.

-- 
You are receiving this mail because:
You are on the CC list for the bug.
___
bug-binutils mailing list
bug-binutils@gnu.org
https://lists.gnu.org/mailman/listinfo/bug-binutils