Subject: Re: The ares_create_query security vulnerability

Re: The ares_create_query security vulnerability

From: bch <brad.harder_at_gmail.com>
Date: Sun, 16 Oct 2016 09:07:10 -0700

I read it, and it's incredibly interesting. I sure hope there's follow up
material for this...

-bch

On Oct 16, 2016 8:12 AM, "Daniel Stenberg" <daniel_at_haxx.se> wrote:

> Hi friends,
>
> Just wanted to mention that the CVE-2016-5180 problem we fixed back on
> September 29th in c-ares 1.12.0 played an important part in root code
> execution exploit, and yesterday I blogged some details for those
> interested:
>
> https://daniel.haxx.se/blog/2016/10/14/a-single-byte-write-
> opened-a-root-execution-exploit/
>
> --
>
> / daniel.haxx.se
>
Received on 2016-10-16