[Bug 1912050] Re: Use after free in libgetdata v0.10.0 may lead to arbitrary code execution

2021-05-31 Thread Carlos Andres Ramirez
Thank you Alex, Steve, The developer did not respond, so I guess Red Hat Security team decided to act on the vulnerability advisory. Thank you guys for following up on this. --- Carlos -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 1912091] Re: Memory Leak GNU Tar 1.33

2021-01-18 Thread Carlos Andres Ramirez
Update: CVE-2021-20193 has been assigned to this vulnerability by Red Hat Security team. --- Carlos ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-20193 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1912091] Re: Memory Leak GNU Tar 1.33

2021-01-17 Thread Carlos Andres Ramirez
Update This vulnerability has been discussed with the developer. Developer has released a public fix. Original Post in GNU TAR Project: https://savannah.gnu.org/bugs/?59897 Commit with fix: https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777 This thread