Re: [OE-core] [dizzy][PATCH] coreutils: Fix CVE-2014-9471

2015-01-20 Thread akuster808
thanks for the reminder. merged into my staging for dizzy-next - armin On 01/19/2015 05:57 AM, Maxin B. John wrote: Gentle ping on this. On Wed, Jan 07, 2015 at 01:11:43PM +0100, Maxin B. John wrote: Fiedler Roman discovered that coreutils' parse_datetime() function has some flaws that may

Re: [OE-core] [dizzy][PATCH] coreutils: Fix CVE-2014-9471

2015-01-20 Thread Maxin B. John
Hi Ross, On Tue, Jan 20, 2015 at 04:00:02PM +, Burton, Ross wrote: On 19 January 2015 at 13:57, Maxin B. John maxin.j...@enea.com wrote: On Wed, Jan 07, 2015 at 01:11:43PM +0100, Maxin B. John wrote: Fiedler Roman discovered that coreutils' parse_datetime() function has

Re: [OE-core] [dizzy][PATCH] coreutils: Fix CVE-2014-9471

2015-01-20 Thread Burton, Ross
On 19 January 2015 at 13:57, Maxin B. John maxin.j...@enea.com wrote: On Wed, Jan 07, 2015 at 01:11:43PM +0100, Maxin B. John wrote: Fiedler Roman discovered that coreutils' parse_datetime() function has some flaws that may be exploitable if the date(1), touch(1), or potentially other

[OE-core] [dizzy][PATCH] coreutils: Fix CVE-2014-9471

2015-01-07 Thread Maxin B. John
Fiedler Roman discovered that coreutils' parse_datetime() function has some flaws that may be exploitable if the date(1), touch(1), or potentially other programs, accept untrusted input for certain parameters. While researching this issue, he discovered that it was independently discovered by