Bug#528778: [Secure-testing-team] Bug#528778: eggdrop: incomplete patch for CVE-2007-2807

2009-05-15 Thread Nico Golde
Hi, * Michael S. Gilbert [2009-05-15 19:45]: > On Fri, 15 May 2009 14:18:26 +0200, Nico Golde wrote: [...] > > turns out my patch has a bug in it which opens this up for a > > buffer overflow again in case strlen(ctcpbuf) returns 0: > > http://www.gossamer-threads.com/lists/fulldisc/full-disclosu

Bug#528778: [Secure-testing-team] Bug#528778: eggdrop: incomplete patch for CVE-2007-2807

2009-05-15 Thread Michael S. Gilbert
On Fri, 15 May 2009 14:18:26 +0200, Nico Golde wrote: > Package: eggdrop > Severity: grave > Tags: security > Justification: user security hole > > Hi, > turns out my patch has a bug in it which opens this up for a > buffer overflow again in case strlen(ctcpbuf) returns 0: > http://www.gossamer-th

Bug#528778: eggdrop: incomplete patch for CVE-2007-2807

2009-05-15 Thread Nico Golde
Package: eggdrop Severity: grave Tags: security Justification: user security hole Hi, turns out my patch has a bug in it which opens this up for a buffer overflow again in case strlen(ctcpbuf) returns 0: http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/68341 Too bad noone noticed t