Actions
Security #4420
closed
JL
JI
Heap-use-after-free READ 8 · JsonDNP3LoggerToClient
Security #4420:
Heap-use-after-free READ 8 · JsonDNP3LoggerToClient
Git IDs:
Severity:
Disclosure Date:
Description
Found by oss-fuzz
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31549
Use after realloc
DNP3 seems the only one to use OutputJsonBuilderBuffer dangerously
JL Updated by Jeff Lucovsky about 5 years ago
- Copied from Bug #4387: Heap-use-after-free READ 8 · JsonDNP3LoggerToClient added
JI Updated by Jason Ish almost 5 years ago
The commit's to master are not applicable to 6.0 as master was fixed due to some other refactoring. For 6.0.x we can use Philippe's original fix for this issue:
JI Updated by Jason Ish almost 5 years ago
Fix for 6.0.3: https://gitlab.oisf.net/dev/suricata/-/merge_requests/213
JI Updated by Jason Ish almost 5 years ago
- Status changed from Assigned to In Review
SB Updated by Shivani Bhardwaj almost 5 years ago
- Assignee changed from Shivani Bhardwaj to Jason Ish
VJ Updated by Victor Julien almost 5 years ago
- Tracker changed from Bug to Security
VJ Updated by Victor Julien almost 5 years ago
- Status changed from In Review to Closed
VJ Updated by Victor Julien over 4 years ago
- Private changed from Yes to No
Actions