From 5cefe3fc8f35b50eb84cbb740268539a40651173 Mon Sep 17 00:00:00 2001 From: Allan McRae Date: Sat, 21 Jun 2014 17:23:55 +1000 Subject: [PATCH] Mention CVE-2014-4043 in NEWS --- ChangeLog | 4 ++++ NEWS | 6 ++++++ 2 files changed, 10 insertions(+) diff --git a/ChangeLog b/ChangeLog index 45675f296e0..b399a9b1433 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,7 @@ +2014-06-21 Allan McRae + + * NEWS: Mention CVE-2014-4043. + 2014-06-11 Florian Weimer [BZ #17048] diff --git a/NEWS b/NEWS index b6d603aeb81..7aa51f15593 100644 --- a/NEWS +++ b/NEWS @@ -32,6 +32,12 @@ Version 2.19.1 silently replaced with the "C" locale when running in AT_SECURE mode (e.g., in a SUID program). This is no longer necessary because of the additional checks. + +* CVE-2014-4043 The posix_spawn_file_actions_addopen implementation did not + copy the path argument. This allowed programs to cause posix_spawn to + deference a dangling pointer, or use an unexpected pathname argument if + the string was modified after the posix_spawn_file_actions_addopen + invocation. Version 2.19 -- 2.47.2