Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pcal | Pcal | 4.1.0 (including) | 4.1.0 (including) |
Pcal | Pcal | 4.3.0 (including) | 4.3.0 (including) |
Pcal | Pcal | 4.5.0 (including) | 4.5.0 (including) |
Pcal | Pcal | 4.6.0 (including) | 4.6.0 (including) |
Pcal | Pcal | 4.7.0 (including) | 4.7.0 (including) |
Pcal | Pcal | 4.7.1 (including) | 4.7.1 (including) |
Pcal | Ubuntu | dapper | * |
Pcal | Ubuntu | devel | * |
Pcal | Ubuntu | edgy | * |
Pcal | Ubuntu | feisty | * |