Un problema è stato scoperto nel GNU gettext 0.19.8. C’è un doppio trasporto default_add_message in lettura catalog.c correlato a una connessione valida nel po_gram_parse in po-gram-gen.y, come dimostrato da lt-msgfmt. |
https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/doublefree https://github.com/CCCCCrash/POCs/tree/master/Bin/Tools-gettext-0.19.8.1/heapcorruption https://access.redhat.com/errata/RHSA-2019:3643 http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00061.html http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00065.html http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00025.html https://usn.ubuntu.com/3815-1/ https://usn.ubuntu.com/3815-2/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18751 |
Vulnerabilità: CVE-2018-18751
