Bug#876659: ledger: CVE-2017-2808: Ledger CLI Account Directive Use-After-Free Vulnerability

2019-01-26 Thread Salvatore Bonaccorso
Hi Martin, On Sat, Jan 26, 2019 at 01:18:17PM -0300, Martin Michlmayr wrote: > * Salvatore Bonaccorso [2017-09-24 17:57]: > > the following vulnerability was published for ledger. > > > > CVE-2017-2808[0]: > > | An exploitable use-after-free vulnerability exists in the account > > This has

Bug#876659: ledger: CVE-2017-2808: Ledger CLI Account Directive Use-After-Free Vulnerability

2019-01-26 Thread Martin Michlmayr
* Salvatore Bonaccorso [2017-09-24 17:57]: > the following vulnerability was published for ledger. > > CVE-2017-2808[0]: > | An exploitable use-after-free vulnerability exists in the account This has been fixed upstream:

Bug#876659: ledger: CVE-2017-2808: Ledger CLI Account Directive Use-After-Free Vulnerability

2017-09-24 Thread Salvatore Bonaccorso
Source: ledger Version: 3.1.2~pre1+g3a00e1c+dfsg1-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for ledger. CVE-2017-2808[0]: | An exploitable use-after-free vulnerability exists in the account | parsing component of the Ledger-CLI 3.1.1. A