S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
http://lists.jedsoft.org/lists/slang-users/2023/0000002.html | mailing list |
http://seclists.org/fulldisclosure/2024/Jan/57 | mailing list |