From 46d54873c379cb1a3acc501587a5bc22c0767b38 Mon Sep 17 00:00:00 2001 From: Florian Weimer Date: Fri, 6 Feb 2015 16:28:24 +0100 Subject: NEWS: Also mention CVE-2015-1473 --- NEWS | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/NEWS b/NEWS index 1f839bce2a..585eda6051 100644 --- a/NEWS +++ b/NEWS @@ -27,10 +27,11 @@ Version 2.21 17801, 17803, 17806, 17834, 17844, 17848, 17868, 17869, 17870, 17885, 17892. -* CVE-2015-1472 Under certain conditions wscanf can allocate too little - memory for the to-be-scanned arguments and overflow the allocated - buffer. The implementation now correctly computes the required buffer - size when using malloc. +* CVE-2015-1472 CVE-2015-1473 Under certain conditions wscanf can allocate + too little memory for the to-be-scanned arguments and overflow the + allocated buffer. The implementation now correctly computes the required + buffer size when using malloc, and switches to malloc from alloca as + intended. * A new semaphore algorithm has been implemented in generic C code for all machines. Previous custom assembly implementations of semaphore were -- cgit 1.4.1