New Release: 4.0.1 -- Fixes Potential Security Vulnerability
Chad Walstrom <[email protected]> Thu, 11 Nov 2004 16:57:49 -0600
| Newsgroups | gmane.comp.bug-tracking.gnats.announce |
|---|---|
| Message-ID | <[email protected]> |
--===============1611964502== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="8RsyD0KswhpoK73Z" Content-Disposition: inline --8RsyD0KswhpoK73Z Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable The GNU GNATS Development Team has released a new version of GNATS, the Problem Report Management System. This release, 4.0.1 is a patch release to address a potential security vulnerability with string formatting in gnats/misc.c that was described in: http://lists.gnu.org/archive/html/bug-gnats/2004-06/msg00028.html http://www.zone-h.org/advisories/read/id=3D4889 http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCAN-2004-0623 http://www.debian.org/security/2004/dsa-590 Additional string formatting fixes were applied to avoid buffer overflows in constructing formatted date strings. You may download GNATS 4.0.1 from ftp://ftp.gnu.org/pub/gnu/gnats/ or http://savannah.gnu.org/download/gnats (temporarily). --=20 Chad Walstrom <[email protected]> http://www.wookimus.net/ assert(expired(knowledge)); /* core dump */ --8RsyD0KswhpoK73Z Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD4DBQFBk+5tDMcLGCBsWv0RAqGnAJwPbC4HqDxBmwq7LCW3RazbD0/x7gCUC/GA O5rqqJj9f46VvqSoHHT3Nw== =QvY7 -----END PGP SIGNATURE----- --8RsyD0KswhpoK73Z-- --===============1611964502== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Info-gnats mailing list [email protected] http://lists.gnu.org/mailman/listinfo/info-gnats --===============1611964502==--