[Secure-testing-team] Bug#551070: CVE-2009-3575: Buffer overflow in DHTRoutingTableDeserializer.cc
Giuseppe Iuculano
giuseppe at iuculano.it
Thu Oct 15 12:10:52 UTC 2009
Package: aria2
Version: 0.14.0-1
Severity: serious
Tags: security patch
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for aria2.
CVE-2009-3575[0]:
| Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3,
| 1.2.0, and other versions allows remote attackers to cause a denial of
| service (crash) and possibly execute arbitrary code via unknown
| vectors.
This is already fixed in debian unstable.
Please coordinate with the security team (team at security.debian.org) to
prepare packages for the stable and oldstable releases.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3575
http://security-tracker.debian.net/tracker/CVE-2009-3575
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkrXET8ACgkQNxpp46476aqpIACdGwJaJcOsmW7L88qDBPK/fczw
LC4An2Sk0eMCR+ztgGwI/3dTkv8vunod
=JWV0
-----END PGP SIGNATURE-----
More information about the Secure-testing-team
mailing list