Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <1339886535.650476.1307991864519.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 13 Jun 2011 15:04:24 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: vladz <vladz@...zero.fr>, Josselin Mouette <joss@...ian.org>,
        Behdad Esfahbod <behdad@...me.org>, Christian Persch <chpe@...me.org>,
        Josselin Mouette <joss@...sain.org>,
        "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request -- vte -- Excessive memory and CPU
 use by processing certain character sequences



----- Original Message -----
> Hello, Josh, Steve, vendors,
> 
> An memory exhaustion flaw was found in the way VTE, a terminal
> emulator widget, processed certain character sequences. A remote
> attacker could provide a specially-crafted file, which once opened
> in a terminal using the VTE terminal emulator could lead to excessive
> memory and CPU consumption (leading to subsequent particular process
> termination by OOM killer on some systems).
> 
> References:
> [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629688
> [2] https://bugzilla.gnome.org/show_bug.cgi?id=652124
> [3] https://bugzilla.redhat.com/show_bug.cgi?id=712148
> 

Please use CVE-2011-2198.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.