Bug#750815: musl: CVE-2014-3484: remote stack-based buffer overflow in DNS response

2014-06-11 Thread Kevin Bortis
The musl package 1.1.2 is packaged and ready for upload. Unfortunatly Debian unstable has switched to gcc-4.9 as their default compiler, which introduces a serious bug in weak alias constant folding. A possible patch is attached to the upstream gcc bug, but is currently not applied or reviewed by t

Bug#750815: musl: CVE-2014-3484: remote stack-based buffer overflow in DNS response

2014-06-06 Thread Salvatore Bonaccorso
Source: musl Severity: grave Tags: security upstream fixed-upstream Hi, the following vulnerability was published for musl. CVE-2014-3484[0]: remote stack-based buffer overflow in DNS response If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposu