[Bug locale/34520] New: Buffer overflow in localedef wide string parsing
fweimer at redhat dot com via Glibc-bugs <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.bugs |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://sourceware.org/bugzilla/show_bug.cgi?id=34520
Bug ID: 34520
Summary: Buffer overflow in localedef wide string parsing
Product: glibc
Version: unspecified
Status: NEW
Severity: normal
Priority: P2
Component: locale
Assignee: unassigned at sourceware dot org
Reporter: fweimer at redhat dot com
Target Milestone: ---
Flags: security-
Created attachment 16935
--> https://sourceware.org/bugzilla/attachment.cgi?id=16935&action=edit
RHEL-217266.html
I've been asked to forward this upstream. It's not a vulnerability because
locale definitions are inherently trusted.
The issue is that get_string in locale/programs/linereader.c confuses byte
counts and wide character counts.
I've been asked to mention: Found by AISLE in partnership with Red Hat
--
You are receiving this mail because:
You are on the CC list for the bug.