From f5b3338d70a7a2c626331ac4589b6deb2f610432 Mon Sep 17 00:00:00 2001 From: Florian Weimer Date: Fri, 29 Apr 2016 10:47:40 +0200 Subject: [PATCH] NEWS entry for CVE-2016-3075 --- NEWS | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/NEWS b/NEWS index aa6209e..24e13ae 100644 --- a/NEWS +++ b/NEWS @@ -27,6 +27,10 @@ Version 2.24 Security related changes: +* An unnecessary stack copy in _nss_dns_getnetbyname_r was removed. It + could result in a stack overflow when getnetbyname was called with an + overly long name. (CVE-2016-3075) + * Previously, getaddrinfo copied large amounts of address data to the stack, even after the fix for CVE-2013-4458 has been applied, potentially resulting in a stack overflow. getaddrinfo now uses a heap allocation -- 2.7.4