The situation with libwww.

Kenneth Porter shiva at sewingwitch.com
Sun Jun 5 11:43:53 UTC 2005


--On Saturday, June 04, 2005 4:46 PM -0400 Sam Varshavchik 
<mrsam at courier-mta.com> wrote:

> A minor update.  Upon further investigation one of the bugs turned into
> an illegal out-of-bounds memory access, which, I guess makes it a
> security issue.
>
> Any hostile server could now potentially cause any libwww client to
> segfault, from the looks of things.  This includes the LWP module.  What
> a gawdawful mess?
>
> The function which is responsible for this mess is beyond hope, and must
> be rewritten.

I don't see the issues listed here:

<https://bugzilla.redhat.com/bugzilla/buglist.cgi?component=w3c-libwww>

You might want to file new entries for these.





More information about the users mailing list