Re: Bug in return_append_str
Antonio Ceballos Roa <[email protected]> Tue, 4 Jul 2017 07:20:49 +0200
| Newsgroups | gmane.comp.gnu.chess.bugs |
|---|---|
| Message-ID | <[email protected]> |
--===============3711640761118195680== Content-Type: multipart/alternative; boundary=Apple-Mail-4EB0766B-61B5-4381-8C42-E8D1C4C2D020 Content-Transfer-Encoding: 7bit --Apple-Mail-4EB0766B-61B5-4381-8C42-E8D1C4C2D020 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Mark, Thanks. It seems quite evident. I will try to set up a scenario to catch it w= ith valgrind though. Do you think it would be easy? I believe you deem it un= necessary, right? Thanks, Antonio > El 3 jul 2017, a las 9:09, Mark Hermeling <[email protected]> escr= ibi=C3=B3: >=20 > Antonio, >=20 > That is certainly true once the modification that I proposed is applied. Y= ou need to allocate the space of the string, plus one character for the EOL.= However, with the current code you allocate enough memory for the string an= d then move the pointer one character to the right. It is a simple typo, the= brackets are placed incorrectly.=20 >=20 > Regards, > Mark >=20 > -- > Sent from my phone, please excuse any typos.=20 >=20 >=20 >> On Jul 3, 2017, at 00:14, Antonio Ceballos <[email protected]> wrote: >>=20 >> Hi Mark, >>=20 >> Thanks for finding this potential bug and for providing a fix. However, H= ow would you reply to the comment that is written right before the line you m= entioned (I am not the author): >>=20 >> /* This doesn't have buffer overflow vulnerabilities, because >> we always allocate for enough space before appending. */ >>=20 >> Thanks, >> Antonio Ceballos >>=20 >>=20 >>> On Fri, Jun 30, 2017 at 2:20 PM, Mark Hermeling <[email protected]= om> wrote: >>> Hello, >>>=20 >>> There is a buffer overrun in return_append_str in src/frontend/lexpgn.cc= at line >>> 2224 newloc =3D (char *) malloc(strlen(s))+1; >>>=20 >>> The line should read: >>> newloc =3D (char *) malloc(strlen(s)+1); >>>=20 >>> We found this using static analysis using CodeSonar. I don=E2=80=99t hav= e an actual path that will demonstrate this bug. >>>=20 >>> Regards, >>> Mark >>>=20 >>> =E2=80=94 >>> Mark Hermeling | GrammaTech | Senior Director Product Marketing >>> mobile +1 (607) 351-5719 | www.grammatech.com >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>>=20 >>> _______________________________________________ >>> Bug-gnu-chess mailing list >>> [email protected] >>> https://lists.gnu.org/mailman/listinfo/bug-gnu-chess >>>=20 >>=20 --Apple-Mail-4EB0766B-61B5-4381-8C42-E8D1C4C2D020 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><div>Mark,</div><div id=3D"AppleMailSignatu= re"><br></div><div id=3D"AppleMailSignature">Thanks. It seems quite evident.= I will try to set up a scenario to catch it with valgrind though. Do you th= ink it would be easy? I believe you deem it unnecessary, right?<br><br>Thank= s,<br>Antonio</div><div><br>El 3 jul 2017, a las 9:09, Mark Hermeling <<a= href=3D"mailto:[email protected]">[email protected]</a>>= escribi=C3=B3:<br><br></div><blockquote type=3D"cite"><div><meta http-equiv= =3D"content-type" content=3D"text/html; charset=3Dutf-8"><div>Antonio,</div>= <div id=3D"AppleMailSignature"><br></div><div id=3D"AppleMailSignature">That= is certainly true once the modification that I proposed is applied. You nee= d to allocate the space of the string, plus one character for the EOL. Howev= er, with the current code you allocate enough memory for the string and then= move the pointer one character to the right. It is a simple typo, the brack= ets are placed incorrectly. </div><div id=3D"AppleMailSignature"><br></= div><div id=3D"AppleMailSignature">Regards,</div><div id=3D"AppleMailSignatu= re">Mark<br><br>--<div>Sent from my phone, please excuse any typos. </d= iv><div><br></div></div><div><br>On Jul 3, 2017, at 00:14, Antonio Ceballos &= lt;<a href=3D"mailto:[email protected]">[email protected]</a>> wrote:= <br><br></div><blockquote type=3D"cite"><div><div dir=3D"ltr">Hi Mark,<div><= br></div><div>Thanks for finding this potential bug and for providing a fix.= However, How would you reply to the comment that is written right before th= e line you mentioned (I am not the author):</div><div><br></div><div><div>&n= bsp; /* This doesn't have buffer overflow vulnerabilities, because</d= iv><div> we always allocate for enough space befor= e appending. */</div></div><div><br></div><div>Thanks,</div><div>Antonio Ceb= allos</div><div><br></div></div><div class=3D"gmail_extra"><br><div class=3D= "gmail_quote">On Fri, Jun 30, 2017 at 2:20 PM, Mark Hermeling <span dir=3D"l= tr"><<a href=3D"mailto:[email protected]" target=3D"_blank">mherm= [email protected]</a>></span> wrote:<br><blockquote class=3D"gmail_quo= te" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">= <div style=3D"word-wrap:break-word">Hello,<div><br></div><div>There is a buf= fer overrun in return_append_str in src/frontend/<a href=3D"http://lexpgn.cc= " target=3D"_blank">lexpgn.cc</a> at line</div><div><table cellspacing=3D"0"= cellpadding=3D"0" style=3D"width:1273px;margin:0px;border:none;color:rgb(0,= 0,0);font-family:sans-serif"><tbody><tr class=3D"m_7236857695585029220vc_row= _odd" id=3D"m_7236857695585029220l2224" style=3D"vertical-align:top;backgrou= nd-color:rgb(240,240,240)"><td class=3D"m_7236857695585029220vc_file_line_nu= mber" style=3D"vertical-align:top;border-right-width:1px;background-color:rg= b(238,238,238);color:rgb(80,80,80);text-align:right;border-right-style:solid= ;border-right-color:rgb(80,80,80);padding:1px 5px">2224</td><td class=3D"m_7= 236857695585029220vc_file_line_text" style=3D"vertical-align:top;border-righ= t-width:0px;background-color:white;font-family:monospace;white-space:pre-wra= p;width:1216.40625px;border-right-style:solid;border-right-color:rgb(80,80,8= 0);padding:1px 5px"> <span class=3D"m_7236857695585029220pygm= ents-n">newloc</span> <span class=3D"m_7236857695585029220pygments-o" style=3D= "color:rgb(102,102,102)">=3D</span> <span class=3D"m_7236857695585029220pygm= ents-p">(</span><span class=3D"m_7236857695585029220pygments-kt" style=3D"co= lor:rgb(176,0,64)">char</span> <span class=3D"m_7236857695585029220pygments-= o" style=3D"color:rgb(102,102,102)">*</span><span class=3D"m_723685769558502= 9220pygments-p">)</span> <span class=3D"m_7236857695585029220pygments-n">mal= loc</span><span class=3D"m_7236857695585029220pygments-p">(</span><span clas= s=3D"m_7236857695585029220pygments-n">strlen</span><span class=3D"m_72368576= 95585029220pygments-p">(</span><span class=3D"m_7236857695585029220pygments-= n">s</span><span class=3D"m_7236857695585029220pygments-p">))</span><span cl= ass=3D"m_7236857695585029220pygments-o" style=3D"color:rgb(102,102,102)">+</= span><span class=3D"m_7236857695585029220pygments-mi" style=3D"color:rgb(102= ,102,102)">1</span><span class=3D"m_7236857695585029220pygments-p">;</span><= /td></tr></tbody></table><div><br></div></div><div>The line should read:</di= v><div><span class=3D"m_7236857695585029220pygments-n" style=3D"font-family:= monospace;white-space:pre-wrap;background-color:rgb(255,255,255)">newloc</sp= an><span style=3D"font-family:monospace;font-size:medium;white-space:pre-wra= p;background-color:rgb(255,255,255)"> </span><span class=3D"m_72368576955850= 29220pygments-o" style=3D"font-family:monospace;white-space:pre-wrap;backgro= und-color:rgb(255,255,255);color:rgb(102,102,102)">=3D</span><span style=3D"= font-family:monospace;font-size:medium;white-space:pre-wrap;background-color= :rgb(255,255,255)"> </span><span class=3D"m_7236857695585029220pygments-p" s= tyle=3D"font-family:monospace;white-space:pre-wrap;background-color:rgb(255,= 255,255)">(</span><span class=3D"m_7236857695585029220pygments-kt" style=3D"= font-family:monospace;white-space:pre-wrap;background-color:rgb(255,255,255)= ;color:rgb(176,0,64)">char</span><span style=3D"font-family:monospace;font-s= ize:medium;white-space:pre-wrap;background-color:rgb(255,255,255)"> </span><= span class=3D"m_7236857695585029220pygments-o" style=3D"font-family:monospac= e;white-space:pre-wrap;background-color:rgb(255,255,255);color:rgb(102,102,1= 02)">*</span><span class=3D"m_7236857695585029220pygments-p" style=3D"font-f= amily:monospace;white-space:pre-wrap;background-color:rgb(255,255,255)">)</s= pan><span style=3D"font-family:monospace;font-size:medium;white-space:pre-wr= ap;background-color:rgb(255,255,255)"> </span><span class=3D"m_7236857695585= 029220pygments-n" style=3D"font-family:monospace;white-space:pre-wrap;backgr= ound-color:rgb(255,255,255)">malloc</span><span class=3D"m_72368576955850292= 20pygments-p" style=3D"font-family:monospace;white-space:pre-wrap;background= -color:rgb(255,255,255)">(</span><span class=3D"m_7236857695585029220pygment= s-n" style=3D"font-family:monospace;white-space:pre-wrap;background-color:rg= b(255,255,255)">strlen</span><span class=3D"m_7236857695585029220pygments-p"= style=3D"font-family:monospace;white-space:pre-wrap;background-color:rgb(25= 5,255,255)">(</span><span class=3D"m_7236857695585029220pygments-n" style=3D= "font-family:monospace;white-space:pre-wrap;background-color:rgb(255,255,255= )">s</span><span class=3D"m_7236857695585029220pygments-p" style=3D"font-fam= ily:monospace;white-space:pre-wrap;background-color:rgb(255,255,255)">)+1)</= span><span class=3D"m_7236857695585029220pygments-p" style=3D"font-family:mo= nospace;white-space:pre-wrap;background-color:rgb(255,255,255)">;</span></di= v><div><span class=3D"m_7236857695585029220pygments-p" style=3D"font-family:= monospace;white-space:pre-wrap;background-color:rgb(255,255,255)"><br></span= ></div><div><font face=3D"monospace"><span style=3D"background-color:rgb(255= ,255,255)"><span style=3D"white-space:pre-wrap">We found this using static a= nalysis using CodeSonar. I don=E2=80=99t have an actual path that will demon= strate this bug.</span></span></font></div><div><br></div><div>Regards,</div= ><div>Mark</div><div><br><div> <div style=3D"color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-i= ndent:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:= break-word"><div style=3D"color:rgb(0,0,0);letter-spacing:normal;text-align:= start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0p= x;word-wrap:break-word"><div style=3D"color:rgb(0,0,0);letter-spacing:normal= ;text-align:start;text-indent:0px;text-transform:none;white-space:normal;wor= d-spacing:0px;word-wrap:break-word"><div style=3D"color:rgb(0,0,0);letter-sp= acing:normal;text-align:start;text-indent:0px;text-transform:none;white-spac= e:normal;word-spacing:0px;word-wrap:break-word"><div style=3D"color:rgb(0,0,= 0);letter-spacing:normal;text-align:start;text-indent:0px;text-transform:non= e;white-space:normal;word-spacing:0px;word-wrap:break-word"><div style=3D"co= lor:rgb(0,0,0);letter-spacing:normal;text-align:start;text-indent:0px;text-t= ransform:none;white-space:normal;word-spacing:0px;word-wrap:break-word"><div= style=3D"color:rgb(0,0,0);letter-spacing:normal;text-align:start;text-inden= t:0px;text-transform:none;white-space:normal;word-spacing:0px;word-wrap:brea= k-word"><div style=3D"color:rgb(0,0,0);letter-spacing:normal;text-align:star= t;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;wo= rd-wrap:break-word"><div style=3D"word-wrap:break-word"><div style=3D"color:= rgb(0,0,0);font-family:Helvetica;font-size:12px;font-style:normal;font-varia= nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;tex= t-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">=E2=80= =94</div><span class=3D"HOEnZb"><font color=3D"#888888"><div style=3D"color:= rgb(0,0,0);font-family:Helvetica;font-size:12px;font-style:normal;font-varia= nt-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;tex= t-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">Mark H= ermeling | <b>Gramma<font color=3D"#d72332">Tech</font></b> | Seni= or Director Product Marketing<br>mobile <a href=3D"tel:(607)%20351-5719" val= ue=3D"+16073515719" target=3D"_blank">+1 (607) 351-5719</a> | <a href=3D"htt= p://www.grammatech.com" target=3D"_blank">www.grammatech.com</a></div><div s= tyle=3D"color:rgb(0,0,0);font-family:Helvetica;font-size:12px;font-style:nor= mal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-a= lign:start;text-indent:0px;text-transform:none;white-space:normal;word-spaci= ng:0px"><br></div><br class=3D"m_7236857695585029220Apple-interchange-newlin= e"></font></span></div></div><br class=3D"m_7236857695585029220Apple-interch= ange-newline"></div><br class=3D"m_7236857695585029220Apple-interchange-newl= ine"></div><br class=3D"m_7236857695585029220Apple-interchange-newline"></di= v><br class=3D"m_7236857695585029220Apple-interchange-newline"></div><br cla= ss=3D"m_7236857695585029220Apple-interchange-newline"></div><br class=3D"m_7= 236857695585029220Apple-interchange-newline"></div><br class=3D"m_7236857695= 585029220Apple-interchange-newline"></div><br class=3D"m_7236857695585029220= Apple-interchange-newline"><br class=3D"m_7236857695585029220Apple-interchan= ge-newline"> </div> <br></div></div><br>______________________________<wbr>_________________<br>= Bug-gnu-chess mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"https://lists.gnu.org/mailman/listinfo/bug-gnu-chess" rel=3D"nore= ferrer" target=3D"_blank">https://lists.gnu.org/mailman/<wbr>listinfo/bug-gn= u-chess</a><br> <br></blockquote></div><br></div> </div></blockquote></div></blockquote></body></html>= --Apple-Mail-4EB0766B-61B5-4381-8C42-E8D1C4C2D020-- --===============3711640761118195680== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Bug-gnu-chess mailing list [email protected] https://lists.gnu.org/mailman/listinfo/bug-gnu-chess --===============3711640761118195680==--