[Bug locale/34520] New: Buffer overflow in localedef wide string parsing

fweimer at redhat dot com via Glibc-bugs <[email protected]>
Newsgroups gmane.comp.lib.glibc.bugs
Message-ID <[email protected]/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=34520

            Bug ID: 34520
           Summary: Buffer overflow in localedef wide string parsing
           Product: glibc
           Version: unspecified
            Status: NEW
          Severity: normal
          Priority: P2
         Component: locale
          Assignee: unassigned at sourceware dot org
          Reporter: fweimer at redhat dot com
  Target Milestone: ---
             Flags: security-

Created attachment 16935
  --> https://sourceware.org/bugzilla/attachment.cgi?id=16935&action=edit
RHEL-217266.html

I've been asked to forward this upstream. It's not a vulnerability because
locale definitions are inherently trusted.

The issue is that get_string in locale/programs/linereader.c confuses byte
counts and wide character counts.

I've been asked to mention: Found by AISLE in partnership with Red Hat

-- 
You are receiving this mail because:
You are on the CC list for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.