-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi, folks
I'm attempting to determine if the recent CVS security advisory should be
rated as 'high' or 'critical'. The bug involves a global pointer-to-heap
that may be forced to free twice. The issue is whether or not Linux is
fundamentally vulnerable to double-free bugs (which, for example, on BSD
might permit execution of arbitrary code).
The advisory doesn't seem to indicate whether Linux is subject to the same
vulnerabilty to a double-free problem.
Anyone know offhand?
- --
AJ Armstrong
aja@xxxxxxxxxxxxxxxxx
Memes are a hoax. Pass it on.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQE+MbZzSgEAcQ45BAYRAmUNAJ0X7zSKYUg90SWe5iQ5eVT7YZiUoQCeMSw5
e2OfuC6y306qQ2lmoC0/9PU=
=4fhl
-----END PGP SIGNATURE-----
--
gentoo-dev@xxxxxxxxxx mailing list
|