Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix endless loop on invalid 2 Byte input \xa3\x03 (SYSS-16-030) #16

Merged
merged 1 commit into from
Apr 13, 2016
Merged

fix endless loop on invalid 2 Byte input \xa3\x03 (SYSS-16-030) #16

merged 1 commit into from
Apr 13, 2016

Conversation

keisentraut
Copy link

No description provided.

@kazu-yamamoto kazu-yamamoto merged commit ded250a into kazu-yamamoto:master Apr 13, 2016
kazu-yamamoto added a commit that referenced this pull request Apr 13, 2016
@kazu-yamamoto
Copy link
Owner

Thank you for your report. This is a serious bug.

Your patch prevents the endless loop, however, disables pgpdump to analyze anything. The above patch fixes this.

@kazu-yamamoto
Copy link
Owner

Version 0.30 has been released: http://www.mew.org/~kazu/proj/pgpdump/en/

@keisentraut keisentraut deleted the fix_endless_loop branch April 13, 2016 08:50
@keisentraut
Copy link
Author

I wrote cve-assign@mitre.org about this, they assigned CVE-2016-4021 for this vulnerability. Please see
CVE-2016-4021_MITRE_Reply.txt for their answer.

@kazu-yamamoto
Copy link
Owner

@keisentraut Thank your your contribution to make pgpdump more stable!

jsonn pushed a commit to jsonn/pkgsrc that referenced this pull request Jun 3, 2016
0.31 2016/05/09

* Fixing a buffer overrun.

0.30 2016/04/13

* Security fix: kazu-yamamoto/pgpdump#16
jsonn pushed a commit to jsonn/pkgsrc that referenced this pull request Jun 4, 2016
0.31 2016/05/09

* Fixing a buffer overrun.

0.30 2016/04/13

* Security fix: kazu-yamamoto/pgpdump#16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants