Re: [Full-disclosure] Major gcc 4.1.1 and up security issue

2007-01-15 Thread Roflek of TK53
On 1/16/07, Resident_Geek [EMAIL PROTECTED] wrote: That's an integer overflow. It's well known. See Phrack Volume 0x0b, Issue 0x3c, Phile 0x0a for an introduction to this basic issue. Felix' point was that the latest gcc breaks code that is supposed to _detect_ integer overflows. Cheers,

[Full-disclosure] TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling

2007-01-07 Thread Roflek of TK53
PROTECTED], Roflek of TK53 [EMAIL PROTECTED] * Affected program: CenterICQ (http://thekonst.net/centericq/) * Affected versions: 4.9.11 - 4.21.0 * Overwiew: CenterICQ contains support for LiveJournal (http://www.livejournal.com/), such as posting to your own blog, reading other blogs' RSS feeds