Various memory corruption vulnerabilities have been identified during a security audit of the CDF library. The vulnerabilities exist in the code processing CDF files. The vendor has addressed vulnerabilities on 20.7.2009. with CDF library version 3.3. New CDF library 3.3 has 'cdfvalidate' module that will validate CDF files for potential malformed values. Vulnerability discovered by Leon Juranic <leon.juranic@infigo.hr> Other links: http://cdf.gsfc.nasa.gov/html/CDF_v330.html http://secunia.com/advisories/35940
Версия 3.3 стала собирать только libcdf.so вместо прежнего soname, пока не решил, что делать.