Re: [PATCH][WIP][v2] Fix out-of-buffer-boundary reads

2019-03-31 Thread Yuriy M. Kaminskiy
On 31.03.2019 14:23, Yuriy M. Kaminskiy wrote: > FTR, (some) problems that was addressed by this patch was (apparently > independently) rediscovered 3 years later, assigned CVE-2019-38{55...63} > and fixed (differently; I have not checked if fixed code covers all > cases was covered by my patch).

Re: [PATCH][WIP][v2] Fix out-of-buffer-boundary reads

2019-03-31 Thread Yuriy M. Kaminskiy
FTR, (some) problems that was addressed by this patch was (apparently independently) rediscovered 3 years later, assigned CVE-2019-38{55...63} and fixed (differently; I have not checked if fixed code covers all cases was covered by my patch). BTW, _libssh2_check_length() that is extensively used