FreeBSD-SA-21:15.libfetch

Status
Not open for further replies.

admin

Administrator
Staff member
Administrator
The passive mode in FTP communication allows an out of boundary read while libfetch uses strtol to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for *p == '\0' one byte too late because p++ was already performed.
Continue reading...
 
Status
Not open for further replies.
Back
Top