Buffer overflow in the runlastargs function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.6.0-2", "binary_name": "fwknop-apparmor-profile" }, { "binary_version": "2.6.0-2", "binary_name": "fwknop-client" }, { "binary_version": "2.6.0-2", "binary_name": "fwknop-server" }, { "binary_version": "2.6.0-2", "binary_name": "libfko-doc" }, { "binary_version": "2.6.0-2", "binary_name": "libfko-perl" }, { "binary_version": "2.6.0-2", "binary_name": "libfko-python" }, { "binary_version": "2.6.0-2", "binary_name": "libfko2" }, { "binary_version": "2.6.0-2", "binary_name": "libfko2-dbg" }, { "binary_version": "2.6.0-2", "binary_name": "libfko2-dev" } ] }