Re: [OE-core] [dunfell][PATCH] connman: fix CVE-2021-26675, CVE-2021-26676

2021-03-23 Thread Randy MacLeod
On 2021-03-23 7:37 p.m., Randy MacLeod wrote: From: Catalin Enache A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. gdhcp in ConnMan before 1.39 could be used by network-adjacent. attackers to leak sensitive stack

[OE-core] [dunfell][PATCH] connman: fix CVE-2021-26675, CVE-2021-26676

2021-03-23 Thread Randy MacLeod
From: Catalin Enache A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. gdhcp in ConnMan before 1.39 could be used by network-adjacent. attackers to leak sensitive stack information, allowing further exploitation of bugs