• Noah Misch's avatar
    Fix buffer overrun after incomplete read in pullf_read_max(). · 1dc75515
    Noah Misch authored
    Most callers pass a stack buffer.  The ensuing stack smash can crash the
    server, and we have not ruled out the viability of attacks that lead to
    privilege escalation.  Back-patch to 9.0 (all supported versions).
    
    Marko Tiikkaja
    
    Security: CVE-2015-0243
    1dc75515
pgp-pubkey-decrypt.out 32.7 KB