Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 193173 - sys-fs/inotify-tools: inotifytools_snprintf() Buffer Overflow Vulnerability (CVE-2007-5037)
Summary: sys-fs/inotify-tools: inotifytools_snprintf() Buffer Overflow Vulnerability (...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26825/
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-20 13:01 UTC by Robert Buchholz (RETIRED)
Modified: 2007-12-29 01:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-09-20 13:01:41 UTC
From Secunia:
  A vulnerability has been reported in inotify-tools, which can potentially
  be exploited by malicious users to compromise an application using the
  library... The vulnerability is reported in versions prior to 3.11.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-09-20 13:03:35 UTC
Wolfram, please provide an updated ebuild and remove affected versions if that's possible.
Comment 2 Wolfram Schlich (RETIRED) gentoo-dev 2007-09-20 23:39:03 UTC
3.11 is in the tree, all previous ones have been removed (none of them was stable on any architecture anyway).
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2007-09-20 23:48:24 UTC
Thanks a lot, Wolfram. Always a pleasure. :-)