FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

h2o -- heap buffer overflow during logging

Affected packages
h2o < 2.2.5

Details

VuXML ID ce39379f-7eb7-11e8-ab03-00bd7f19ff09
Discovery 2018-06-01
Entry 2018-07-03

Marlies Ruck reports:

Fix heap buffer overflow while trying to emit access log - see references for full details.

CVE-2018-0608: Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.

References

CVE Name CVE-2018-0608
URL https://github.com/h2o/h2o/issues/1775
URL https://github.com/h2o/h2o/releases/tag/v2.2.5