Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Re: GNU Inetutils talkd buffer overflow with long DNS names.

Дата публикации: 15-08-2026 03:33:43

Posted by Collin Funk on Aug 14Collin Funk <collin.funk1 () gmail com> writes:
Red Hat assigned CVE-2026-19720 to this issue yesterday, 2028-08-13.
Collin


Основное содержимое страницы с новостью.

oss-sec logo oss-sec mailing list archives
From: Collin Funk <collin.funk1 () gmail com>
Date: Fri, 14 Aug 2026 20:16:28 -0700

Collin Funk <collin.funk1 () gmail com> writes:

## Timeline

    2026-07-02: Report sent to inetutils-security () gnu org
    2026-07-02: I (Collin Funk) acknowledged the report and asked a few
                questions regarding the issue.
    2026-07-04: Tristan answered those questions.
    2026-07-06: I reproduced the issue updated Tristan with a planned
                timeline for the fix and CVE assignment.
    2026-07-08: Tristan agreed to the timeline and offered to review the
                patch.
    2026-07-11: I wrote the patch and sent it to Tristan.
    2026-07-15: Tristan confirmed the patch worked as expected.
    2026-07-16: Private mail to distros mailing list along with the patch.
    2026-07-24: I wrote this report and sent it to oss-security.

Note that I also requested a CVE when emailing distros, but haven't
heard back. I'll probably reach out privately to a CNA in a bit, and
will update here once one is assigned.

Red Hat assigned CVE-2026-19720 to this issue yesterday, 2028-08-13.

Collin


Current thread:

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Re: CVE Request: BlueZ AVRCP Out-of-Bounds Read (CWE-125)013.1114-08-2026
2CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS07.4113-08-2026
3OpenSSL Security Advisory06.6213-08-2026
4CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for011.5413-08-2026
5CVE-2026-73193: DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse08.7515-08-2026
6CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send09.515-08-2026
7CVE-2026-73194: DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse09.6915-08-2026
8Why Red Hat’s krb5 Update Matters for Linux and Windows Authentication 0514-05-2026
9Vývojáři linuxového jádra přidělili 432 CVE během dvou dnů019.4623-07-2026
10За 31 час разработчики Linux опубликовали 432 сообщения об уязвимостях ядра015.4627-07-2026

Классификация: Информация. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.86. Источник: seclists.org.