Candidate: CVE-2013-4385 PublicDate: 2013-10-09 14:54:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4385 http://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=commit;h=cd1b9775005ebe220ba11265dbf5396142e65f26 http://www.openwall.com/lists/oss-security/2013/09/26/7 http://lists.nongnu.org/archive/html/chicken-announce/2013-09/msg00000.html Description: Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via a "#f" value in the NUM argument. Ubuntu-Description: Notes: Bugs: Priority: high Discovered-by: Assigned-to: CVSS: Patches_chicken: upstream: http://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=commit;h=cd1b9775005ebe220ba11265dbf5396142e65f26 upstream_chicken: released (4.8.0.5, 4.8.3) lucid_chicken: ignored (reached end-of-life) precise_chicken: ignored (reached end-of-life) precise/esm_chicken: DNE (precise was needed) quantal_chicken: ignored (reached end-of-life) raring_chicken: ignored (reached end-of-life) saucy_chicken: ignored (reached end-of-life) trusty_chicken: released (4.8.0.5-1) trusty/esm_chicken: DNE (trusty was released [4.8.0.5-1]) utopic_chicken: ignored (reached end-of-life) vivid_chicken: ignored (reached end-of-life) vivid/stable-phone-overlay_chicken: DNE vivid/ubuntu-core_chicken: DNE wily_chicken: ignored (reached end-of-life) xenial_chicken: not-affected (4.8.0.5-1) yakkety_chicken: not-affected (4.8.0.5-1) zesty_chicken: not-affected (4.8.0.5-1) devel_chicken: not-affected (4.8.0.5-1)