Bug#948463: libai-fann-perl: Integer overflow leading to heap buffer overflow

2020-01-09 Thread gregor herrmann
On Wed, 08 Jan 2020 15:19:47 -0700, Jayakrishna Vadayath wrote: > As a part of an academic project, we have discovered an integer overflow > which can lead to a heap buffer overflow in the libai-fann-package. Thanks for your bug report and your work. As this is not a bug in the packaging, I've f

Bug#948463: libai-fann-perl: Integer overflow leading to heap buffer overflow

2020-01-08 Thread Jayakrishna Vadayath
Package: libai-fann-perl Severity: normal Dear Maintainer, As a part of an academic project, we have discovered an integer overflow which can lead to a heap buffer overflow in the libai-fann-package. The vulnerability lies in morefann.c:allocvv where two user controlled integers are used in a mu