Pro / tinysvcmdns

Fork from https://bitbucket.org/geekman/tinysvcmdns
Other
6 stars 2 forks source link

Fix for CVE-2017-12087 #2

Open Botje opened 6 years ago

Botje commented 6 years ago

At the end of November, a vulnerability CVE-2017-12087 was found in the nlabel_to_str function, which has since been patched. Another fork of Tinysvcmdns patched it shortly after: mikebrady/shairport-sync#621

Botje commented 6 years ago

Note: this function is only used as part of debug prints, so removing or ifdef-ing the calls is another option.