Hello Brendan,

Your message was waiting for moderation because it is too big. That's why it took forever, sorry about that.

Thank you for your patches, I just applied them in the master branch. As a reference, read this ticket: https://projects.savoirfairelinux.com/issues/4952

Cheers

Manu.

On 10-12-07 06:04 PM, Brendan Smith wrote:


---------- Forwarded message ----------
From: *Brendan Smith* <[email protected] <mailto:[email protected]>>
Date: Tue, Dec 7, 2010 at 4:54 PM
Subject: Possible Security Bugs in sflphone-0.9.11
To: [email protected] <mailto:[email protected]>


Hello

I was looking through the program and found the following security bugs:

In sflphone-0.9.11/sflphone-common/src/main.cpp I found 3 possible buffer overflows in main.cpp. If an attacker can exploit the sfldir buffer, they can get control of the system.

In sflphone-0.9.11/sflphone-client-gnome/src/config/assistant.c I found 3 more buffer overflows in the code.

I am submitting 2 patch.txt files to show the changes I made and 2 patched files for both sets of security bugs.

Thank You
Brendan Smith


_______________________________________________
SFLphone mailing list
[email protected]
http://lists.savoirfairelinux.net/mailman/listinfo/sflphone


--

*Emmanuel Milou*
Consultant en logiciel libre / Free software consultant
/Savoir-faire Linux Inc/
514-276-5468 ext 136
_______________________________________________
SFLphone mailing list
[email protected]
http://lists.savoirfairelinux.net/mailman/listinfo/sflphone

Reply via email to