NFLX-2016-002
Heap Overflow in Dynomite yaml configuration parser.
David Moore / [email protected]
Scott Behrens / [email protected]
06/06/2016
Dynomite
https://github.com/Netflix/dynomite
Medium
A dynomite admin can make a controlled 6 byte write to memory via a crafted dynomite.yml file resulting in heap corruption and possibly remote code execution and privilege escalation.
The master branch contains the fix. The commit can be found here: https://github.com/Netflix/dynomite/commit/93357f74c73648316e65b6676a30355f4c46d09b