Buffer overflow in the runlastargs function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "fwknop-apparmor-profile", "binary_version": "2.6.0-2" }, { "binary_name": "fwknop-client", "binary_version": "2.6.0-2" }, { "binary_name": "fwknop-server", "binary_version": "2.6.0-2" }, { "binary_name": "libfko-doc", "binary_version": "2.6.0-2" }, { "binary_name": "libfko-perl", "binary_version": "2.6.0-2" }, { "binary_name": "libfko-python", "binary_version": "2.6.0-2" }, { "binary_name": "libfko2", "binary_version": "2.6.0-2" }, { "binary_name": "libfko2-dbg", "binary_version": "2.6.0-2" }, { "binary_name": "libfko2-dev", "binary_version": "2.6.0-2" } ] }