Menu

#152 [Security] Null pointer deref could lead to possible DoS

v2.1
closed
None
5
2017-04-07
2016-05-19
No

Hi,

http://www.openslp.org/doc/html/UsersGuide/Security.html mentions i should contact jcalcote@novell.com if i have any security related bugs, but it seems the this email address no longer exists. Also the issue below is already public.

Details available at:
http://seclists.org/oss-sec/2016/q2/361

Discussion

  • John Calcote

    John Calcote - 2017-04-07
    • status: open --> accepted
    • assigned_to: John Calcote
    • Group: --> v2.1
     
  • John Calcote

    John Calcote - 2017-04-07

    Huzaifa,

    Thank you for the information regarding this security vulnerability. Please note that I've fixed the Security.html doc on the OpenSLP website to refer to my actual email address.

    John

     
  • John Calcote

    John Calcote - 2017-04-07

    Huzaifa,

    I've fixed this issue in commit 1781 in the openslp mercurial repository. I've also commented on the redhat bugzilla ticket.

    Regards,
    John

     
  • John Calcote

    John Calcote - 2017-04-07
    • status: accepted --> closed
     
  • John Calcote

    John Calcote - 2017-04-07

    NOTE: This is a fix to DEBUG-ONLY code and would never have been an issue in release/production code.

     

Log in to post a comment.

MongoDB Logo MongoDB