[Date Prev][Date Next] [Chronological] [Thread] [Top]

Buffer overflow in liblber (ITS#1345)



Full_Name: Zachary Amsden
Version: TOT
OS: FreeBSD
URL: ftp://ftp.openldap.org/incoming/zach-io-010921.patch
Submission from: (NULL) (208.48.74.2)


If a BerElement is allocated, written to, reset, and written to again, a buffer
overflow may be triggered because the length of the buffer is not correctly
computed
after a ber_reset