Buffer overflow in the runlastargs function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.
{
"binaries": [
{
"binary_version": "2.6.0-2",
"binary_name": "fwknop-apparmor-profile"
},
{
"binary_version": "2.6.0-2",
"binary_name": "fwknop-client"
},
{
"binary_version": "2.6.0-2",
"binary_name": "fwknop-server"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko-doc"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko-perl"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko-python"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko2"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko2-dbg"
},
{
"binary_version": "2.6.0-2",
"binary_name": "libfko2-dev"
}
],
"availability": "No subscription required"
}