Re: Sufficient patch for CVE-2006-0082

Daniel Kobras <[email protected]> Thu, 2 Mar 2006 00:31:18 +0100
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Wed, Mar 01, 2006 at 11:57:44AM -0600, Albert Chin wrote:
> On Wed, Mar 01, 2006 at 05:31:09PM +0100, Daniel Kobras wrote:
> > Format string security fix, addressing CVE-2005-0397 and further related
> > problems. Introduces new function FormatStringNumeric() that allows a
> > single numeric format substitution on untrusted user input.
> 
> Ok, thanks. Looking at the description of CVE-2005-0397 and
> CVE-2006-0082, it would seem applying this patch for CVE-2005-0397
> solves CVE-2006-0082 as well.

Correct. CVE-2006-0082 is not mentioned in the patch description simply
because I wrote it before the number was assigned. But it indeed
addresses both variants of the problem.

Regards,

Daniel.



-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642