Release date:
Updated on: 2013-10-09
Affected Systems:
CHICKEN <= 4.8.0.4
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2013-4385
CHICKEN is the compiler of Scheme programming language.
CHICKEN 4.8.0.4 and earlier versions are used as buffer hours in "# f", and "read-string" in "extras! "An error in the process may cause a buffer overflow. After successful exploitation, arbitrary code can be executed.
<* Source: vendor
Link: http://secunia.com/advisories/55009/
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1012974
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
CHICKEN
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.call-cc.org
Http://lists.nongnu.org/archive/html/chicken-announce/2013-09/msg00000.html