[tin-bugs] Heap Buffer Overflow in tin 2.6.6 via Header Display-Name Quoting
Tristan
TristanInSec at gmail.com
Mon Aug 31 13:40:03 CEST 2026
Hi Urs,
Thank you for the patch. The fix looks correct -- the key change of
tracking the output position and using realloc when the quoted
display-name is longer than the original addresses the overflow.
For the Reported-by / credit, please use: Tristan Madani
Would you like me to request a CVE for this issue?
Regards,
Tristan
More information about the tin-bugs
mailing list