Re: Sufficient patch for CVE-2006-0082
Daniel Kobras <[email protected]> Thu, 2 Mar 2006 00:31:18 +0100
| Newsgroups | gmane.comp.video.graphicsmagick.core |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Mar 01, 2006 at 11:57:44AM -0600, Albert Chin wrote: > On Wed, Mar 01, 2006 at 05:31:09PM +0100, Daniel Kobras wrote: > > Format string security fix, addressing CVE-2005-0397 and further related > > problems. Introduces new function FormatStringNumeric() that allows a > > single numeric format substitution on untrusted user input. > > Ok, thanks. Looking at the description of CVE-2005-0397 and > CVE-2006-0082, it would seem applying this patch for CVE-2005-0397 > solves CVE-2006-0082 as well. Correct. CVE-2006-0082 is not mentioned in the patch description simply because I wrote it before the number was assigned. But it indeed addresses both variants of the problem. Regards, Daniel. ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642