Stack overflow in the bvi package

Bug #252604 reported by Gerard Wagener
256
Affects Status Importance Assigned to Milestone
bvi (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: bvi

Package: bvi
Version: 1.3.2-2
Release: Ubuntu 7.10

In case file names, longer than 203 characters are provided to bvi, a stack based overflow occurs. This can be explained due to the fact that multiple times the function sprintf is used with user controlled input.

Kees Cook (kees)
Changed in bvi:
status: New → Confirmed
Revision history for this message
Gerhard Bürgmann (buergmann) wrote :

Fixed in 1.4.0

Changed in bvi (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.