Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -58,6 +58,37 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + h2o -- heap buffer overflow during logging + + + h2o + 2.2.5 + + + + +

Marlies Ruck reports:

+
+

Fix heap buffer overflow while trying to emit access log + - see references for full details.

+

CVE-2018-0608: Buffer overflow in H2O version 2.2.4 and + earlier allows remote attackers to execute arbitrary code or + cause a denial of service (DoS) via unspecified vectors.

+
+ +
+ + CVE-2018-0608 + https://github.com/h2o/h2o/issues/1775 + https://github.com/h2o/h2o/releases/tag/v2.2.5 + + + 2018-06-01 + 2018-07-03 + +
+ mozilla -- multiple vulnerabilities