Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And as usually some of them are caused by memory corruption:

> Stack overflow in the parsing of IPv4 options (CVE-2019-12256)

>

> Four memory corruption vulnerabilities stemming from erroneous handling of TCP’s Urgent Pointer field (CVE-2019-12255, CVE-2019-12260, CVE-2019-12261, CVE-2019-12263)

>

> Heap overflow in DHCP Offer/ACK parsing in ipdhcpc (CVE-2019-12257)

DoS via NULL dereference in IGMP parsing (CVE-2019-12259)

While a safer language wouldn't make the remaining logical ones disappear, there would be 7 vulnerabilities less.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: