First published: Mon Jun 15 2009(Updated: )
cscope is a mature, ncurses-based, C source-code tree browsing tool.<br>Multiple buffer overflow flaws were found in cscope. An attacker could<br>create a specially crafted source code file that could cause cscope to<br>crash or, possibly, execute arbitrary code when browsed with cscope.<br>(CVE-2004-2541, CVE-2006-4262, CVE-2009-0148, CVE-2009-1577)<br>All users of cscope are advised to upgrade to this updated package, which<br>contains backported patches to fix these issues. All running instances of<br>cscope must be restarted for this update to take effect.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.