[PATCH] CVE-2016-3075: Stack overflow in _nss_dns_getnetbyname_r [BZ #19879]

Florian Weimer fweimer@redhat.com
Tue Mar 29 11:01:00 GMT 2016


This is a minor security issue in nss_dns, triggered by a very long name
passed to getnetbyname.

The defensive copy is not needed because the name may not alias the
output buffer.

Florian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-CVE-2016-3075-Stack-overflow-in-_nss_dns_getnetbynam.patch
Type: text/x-patch
Size: 939 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20160329/fce512f3/attachment.bin>


More information about the Libc-alpha mailing list