Re: TFTP client crash seems to be caused by missing bounds check in makeargv()

Erik Auerswald <[email protected]>
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <[email protected]>
Hi,

On 04.09.22 17:34, Erik Auerswald wrote:
> On 03.09.22 19:07, Erik Auerswald wrote:
>> On Sat, Sep 03, 2022 at 05:39:45PM +0200, Simon Josefsson wrote:
>>> [...]
>>> did you notice some fuzzing report that wasn't fixed?
>> [...]
>> * Problems found in tftp (the code did not change since the report):
>>
>>    * Untrusted Pointer Dereference in getcmd() at 
>> inetutils/src/tftp.c:878
>>      
>> https://lists.gnu.org/archive/html/bug-inetutils/2021-12/msg00018.html
> 
> That seems to be a missing bounds check in makeargv(), similar
> to the old, now fixed, code in telnet.
> 
> I'll look into creating a nice reproducer instead of the one
> found by the fuzzer, adding a test case, and fixing the bug.

That is harder than expected….  Is there a reason *not* to use
the crash input found by the fuzzer in a test for GNU Inetutils?

Thanks,
Erik
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.