Path to this page:
Subject: CVS commit: [pkgsrc-2010Q2] pkgsrc/net/socat
From: Matthias Scheler
Date: 2010-08-13 16:26:23
Message id: 20100813142624.04936175DD@cvs.netbsd.org
Log Message:
Pullup ticket #3206 - requested by tron
net/socat: security update
Revisions pulled up:
- net/socat/Makefile 1.24
- net/socat/distinfo 1.15
---
Module Name: pkgsrc
Committed By: zafer
Date: Thu Aug 12 17:54:14 UTC 2010
Modified Files:
pkgsrc/net/socat: Makefile distinfo
Log Message:
Update socat to 1.7.1.3
Changelog:
security:
fixed a stack overflow vulnerability that occurred when command
line arguments (whole addresses, host names, file names) were longer
than 512 bytes.
Note that this could only be exploited when an attacker was able to
inject data into socat's command line.
Full credits to Felix Grobert, Google Security Team, for finding and
reporting this issue
Files: