First published: Thu Mar 05 2015(Updated: )
It was reported [1] that the OAuth implementation in librest, a helper library for RESTful services part of the GNOME project, incorrectly truncates the pointer returned by the rest_proxy_call_get_url function call, leading to an application crash, or worse. Upstream bug: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=742644">https://bugzilla.gnome.org/show_bug.cgi?id=742644</a> Commit: <a href="https://git.gnome.org/browse/librest/commit/?id=b50ace7738ea038">https://git.gnome.org/browse/librest/commit/?id=b50ace7738ea038</a> [1]: <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - Memory corruption when using oauth because of implicit declaration of rest_proxy_call_get_url" href="show_bug.cgi?id=1183982">https://bugzilla.redhat.com/show_bug.cgi?id=1183982</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome Librest | =0.7.92 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.