[Bug 14811] networking/nslookup.c parse_reply() CVE-2022-28391 patch query

bugzilla at busybox.net bugzilla at busybox.net
Tue Sep 6 16:55:35 UTC 2022


https://bugs.busybox.net/show_bug.cgi?id=14811

--- Comment #2 from Mark Esler <mark.esler at canonical.com> ---
Could the below patches be reviewed for their applicability to bug
14811 and CVE-2022-28391?

https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch

https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the busybox-cvs mailing list