From 76fe56020e7ef354685b2284580ac1630c078a2b Mon Sep 17 00:00:00 2001 From: Siddhesh Poyarekar Date: Tue, 6 Sep 2022 09:31:50 -0400 Subject: Add NEWS entry for CVE-2022-39046 --- NEWS | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index f9bef48..ef274d1 100644 --- a/NEWS +++ b/NEWS @@ -21,7 +21,10 @@ Changes to build and runtime requirements: Security related changes: - [Add security related changes here] + CVE-2022-39046: When the syslog function is passed a crafted input + string larger than 1024 bytes, it reads uninitialized memory from the + heap and prints it to the target log file, potentially revealing a + portion of the contents of the heap. The following bugs are resolved with this release: -- cgit v1.1