Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "boinc",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-amd-opencl",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-client",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-dbg",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-dev",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-manager",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "boinc-nvidia-cuda",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "libboinc-app-dev",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "libboinc-app7",
"binary_version": "7.2.42+dfsg-1"
},
{
"binary_name": "libboinc7",
"binary_version": "7.2.42+dfsg-1"
}
]
}