Skip to content

Version 2.6.10 - security update

Compare
Choose a tag to compare
@kkaempf kkaempf released this 16 Sep 13:46
  • Pthread usage fixes (Alexander Usyskin)
  • Convert sprintf to snprintf and strcpy to strncpy (Tomas Winkler)
  • Fix configure for Windows (Alexander Usyskin)
  • Fix possible denial of service (Adam Majer, Klaus Kaempf)
    CVE-2019-3833:
    "Openwsman, versions up to and including 2.6.9, are vulnerable to
    infinite loop in process_connection() when parsing specially crafted
    HTTP requests. A remote, unauthenticated attacker can exploit this
    vulnerability by sending malicious HTTP request to cause denial of
    service to openwsman server."
  • Many potential NULL dereferences fixed (Alexander Usyskin)