* [CVE-2021-43612][]: heap overflow when parsing too short SONMP
packets. This vulnerability affects the parser which is run in an
unprivileged and chrooted process. It does not allow arbitrary code
- execution. This bug has been fixed in commit [10b24442][] and in
+ execution. This bug has been fixed in commit [73d42680][] and in
version 1.0.13. It has been discovered by Jeremy Galindo.
* [CVE-2020-27827][]: memory exhaustion attack through crafted LLDPU
[a8d3c90f]: https://github.com/lldpd/lldpd/commit/a8d3c90feca548fc0656d95b5d278713db86ff61
[7d60bf30]: https://github.com/lldpd/lldpd/commit/7d60bf30effc4c88f17f3d58ecaa72479f16d4be
[10b24442]: https://github.com/lldpd/lldpd/commit/10b244425662bbbf056a317965f359fdc036da27
+[73d42680]: https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7
{# Local Variables: #}
{# mode: markdown #}