Package: centericq
Severity: grave
Tags: security
A buffer overflow has been found in the VGETSTRING function of
the ktools library included in centericq, which judging from the
description, sounds remotely exploitable. Please see
http://www.zone-h.org/en/advisories/read/id=8480/ for details.
As the mentioned library is used in two other Debian source packages
(motor and orpheus) as well, you should check whether it's feasible
to package it as a separate package and link dynamically.
Cheers,
Moritz
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-2-686
Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15)
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]