[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH] date,touch: test and document large TZ security issue
From: |
Jim Meyering |
Subject: |
Re: [PATCH] date,touch: test and document large TZ security issue |
Date: |
Thu, 27 Apr 2017 17:15:19 +0900 |
On Thu, Apr 27, 2017 at 1:21 PM, Pádraig Brady <address@hidden> wrote:
> Add a test for CVE-2017-7476 which was fixed in gnulib at:
> http://git.sv.gnu.org/gitweb/?p=gnulib.git;a=commitdiff;h=94e01571
>
> * tests/misc/date-tz.sh: Add a new test which overwrites enough
> of the heap to trigger a segfault, even without ASAN enabled.
> * tests/local.mk: Reference the new test.
> * NEWS: Mention the bug fix.
Nice!