Cscope: Many buffer overflows — GLSA 200606-10

Cscope is vulnerable to multiple buffer overflows that could lead to the execution of arbitrary code.

Affected packages

dev-util/cscope on all architectures
Affected versions < 15.5-r6
Unaffected versions >= 15.5-r6

Background

Cscope is a developer's tool for browsing source code.

Description

Cscope does not verify the length of file names sourced in #include statements.

Impact

A user could be enticed to source a carefully crafted file which will allow the attacker to execute arbitrary code with the permissions of the user running Cscope.

Workaround

There is no known workaround at this time.

Resolution

All Cscope users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-util/cscope-15.5-r6"

References

Release date
June 11, 2006

Latest revision
June 11, 2006: 01

Severity
normal

Exploitable
remote

Bugzilla entries