Re: [FD] [CORE-2016-0005] - FreeBSD Kernel amd64_set_ldt Heap Overflow

2016-03-19 Thread jungle Boogie
On 16 March 2016 at 10:30, CORE Advisories Team wrote: > Title: FreeBSD Kernel amd64_set_ldt Heap Overflow > Advisory ID: CORE-2016-0005 > Advisory URL: > http://www.coresecurity.com/content/freebsd-kernel-amd64_set_ldt-heap-overflow > Date published: 2016-03-16 > Date of last update: 2016-03-14

Re: [FD] several issues in SQLite (+ catching up on several other bugs)

2015-04-19 Thread jungle Boogie
On 14 April 2015 at 11:33, Michal Zalewski wrote: > Because of its versatility, SQLite sometimes finds use as the > mechanism behind SQL-style query APIs that are exposed between > privileged execution contexts and less-trusted code. One example of > this is the WebDB / WebSQL mechanism available

Re: [FD] several issues in SQLite (+ catching up on several other bugs)

2015-04-19 Thread jungle Boogie
On 19 April 2015 at 17:08, Michal Zalewski wrote: > Yup. In addition to the crashes, I also sent them probably around > 50-60 assert failures in debug builds, at their request. Most of them > are probably not security relevant, although it would be painful to > analyze them one by one. Nevertheles