From: Allan McRae Date: Sat, 21 Jun 2014 07:23:55 +0000 (+1000) Subject: Mention CVE-2014-4043 in NEWS X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=29fd33140d964e0e08207ceecbf479b85658fcb8;p=thirdparty%2Fglibc.git Mention CVE-2014-4043 in NEWS (cherry picked from commit d03efb2f979defd473955a455d66b949961d26b2) Conflicts: NEWS --- diff --git a/ChangeLog b/ChangeLog index 658bec91d30..cbabc37eb53 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,7 @@ +2014-06-21 Allan McRae + + * NEWS: Mention CVE-2014-4043. + 2014-06-12 Stefan Liebler * posix/spawn_faction_addopen.c: Include string.h. diff --git a/NEWS b/NEWS index 95392942898..4a51ac6b9a7 100644 --- a/NEWS +++ b/NEWS @@ -10,6 +10,12 @@ Version 2.19.1 * The following bugs are resolved with this release: 16545, 16623, 16882, 16885, 16916, 16943, 16958, 17048. + +* CVE-2014-4043 The posix_spawn_file_actions_addopen implementation did not + copy the path argument. This allowed programs to cause posix_spawn to + deference a dangling pointer, or use an unexpected pathname argument if + the string was modified after the posix_spawn_file_actions_addopen + invocation. Version 2.19