Описание
A flaw was found in svxlink's EchoLink proxy implementation. An integer truncation in message-length handling can result in incorrect buffer sizes, leading to potential memory corruption when processing specially crafted proxy messages.
Отчет
svxlink is not shipped in any Red Hat Enterprise product. It is available in Fedora as a community-maintained package.
Меры по смягчению последствий
Update svxlink to version 26.05.1 or later.
Дополнительная информация
Статус:
Important
Дефект:
CWE-681
https://bugzilla.redhat.com/show_bug.cgi?id=2513807svxlink: svxlink: Integer truncation in EchoLink proxy message length
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]