Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-23 Thread Romain Francoise
On Fri, Nov 23, 2018 at 1:06 PM Salvatore Bonaccorso wrote: > Oh well I see, yes then it was not very helpful from my side. Sorry. > Yes you are right. I understand now and as well your concerns on my > report. Given upstream did adress it as such, could you contact > upstream to see what's their

Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-23 Thread Salvatore Bonaccorso
Hi Romain, [Adding Moritz to CC] On Fri, Nov 23, 2018 at 12:33:26PM +0100, Romain Francoise wrote: > Hi Salvatore, > > On Thu, Nov 22, 2018 at 9:53 PM Salvatore Bonaccorso > wrote: > > The "attack" scenario described as follows, that an attacker can cause > > a denial of service (tmux crash)

Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-23 Thread Romain Francoise
Hi Salvatore, On Thu, Nov 22, 2018 at 9:53 PM Salvatore Bonaccorso wrote: > The "attack" scenario described as follows, that an attacker can cause > a denial of service (tmux crash) by "by arranging for a malloc > failure" triggering the issue in format_cb_pane_tabs in format.c > > Does this

Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-22 Thread Salvatore Bonaccorso
Hi Romain, On Thu, Nov 22, 2018 at 06:26:59PM +0100, Romain Francoise wrote: > Hi Salvatore, > > On Wed, Nov 21, 2018 at 8:57 PM Salvatore Bonaccorso > wrote: > > The following vulnerability was published for tmux, the security > > impact is disputable, but just filling this bug for tracking a

Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-22 Thread Romain Francoise
Hi Salvatore, On Wed, Nov 21, 2018 at 8:57 PM Salvatore Bonaccorso wrote: > The following vulnerability was published for tmux, the security > impact is disputable, but just filling this bug for tracking a future > fix. Thanks for the report. Do you know who assigned the CVE id and what their

Bug#914301: tmux: CVE-2018-19387: NULL Pointer Dereference in format_cb_pane_tabs in format.c

2018-11-21 Thread Salvatore Bonaccorso
Source: tmux Version: 2.8-1 Severity: minor Tags: patch security upstream Forwarded: https://github.com/tmux/tmux/issues/1547 Hi, The following vulnerability was published for tmux, the security impact is disputable, but just filling this bug for tracking a future fix. CVE-2018-19387[0]: |