Re: Fwd: fix format security
Simon Josefsson via Gnulib discussion list <[email protected]>
| Newsgroups | gmane.comp.lib.gnulib.bugs |
|---|---|
| Message-ID | <[email protected]> |
Bruno Haible via Gnulib discussion list <[email protected]> writes: > - The security of the translations is guaranteed through the workflow > (xgettext marks the string with '#, c-format', then 'msgfmt -c' verifies > the compatibility of the format string directives in the translation). Is that protection really complete? Consider a printf (_("foo")); expression, and a maliciously crafted translation. Could that crash? I suppose the protection then is that translation files ought to be as well protected as the binary itself, and that the code that loads the translations are carefully written to never load anything that is outside of a trusted installation. But that seems a bit fragile. Some defense in depth against translation message confusion doesn't seem entirely unreasonable IMHO, and the cost of changing the calls into printf ("%s", _("foo")); isn't that big. I've been changing these occurances when I notice them in code I work on. How do gcc avoid warning for this? Is there a special exception for translation messages or gettext.h somehow? /Simon
signature.asc
(application/pgp-signature, 1.3 KB)
-----BEGIN PGP SIGNATURE----- iQOEBAEWCgMsFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmqMjJYbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyFBxzaW1vbkBqb3NlZnNzb24ub3JnwhwmAJgzBFyS zrQWCSsGAQQB2kcPAQEHQAiHK2SL4a8QwZCvX1fkJU5l8aNp2jmw7hrcOfGGsZTr tCVTaW1vbiBKb3NlZnNzb24gPHNpbW9uQGpvc2Vmc3Nvbi5vcmc+iJYEExYIAD4C GwMFCwkIBwIGFQgJCgsCBBYCAwECHgECF4AWIQSx0r0Tdb7LeEz0+MTXPPY4xTwG vgUCaeH1kQUJDmvq3QAKCRDXPPY4xTwGvoViAP9ZUL6yXhpUKudJT+rZvfQ9cw8u ydbUN4WuMdCce65BUwD/YaVCrk75uptX18omVWGZbtviHfw6twiAGbzRflxK9gS4 MwRcks+BFgkrBgEEAdpHDwEBB0DsUwiDmnlwMSNoSF+ByvW0E6TVXou9PKDa9SpZ vKghioj1BBgWCAAmAhsCFiEEsdK9E3W+y3hM9PjE1zz2OMU8Br4FAmngltcFCQ5q i1YAgXYgBBkWCAAdFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAlySz4EACgkQUXIr CP5HRaKnTAEAoB+OWrHmYCK8Cjr1DgPUH7JnhPBmR2DbhR5jPRREEugA+gOMeWmL 6GOpaPfKYLcNhzw4ZnAlxSLY1wq1eANBpiQOCRDXPPY4xTwGvrOwAPoCCB6QQKQ6 XA49bCocw54Jqb8EH9FZB5nurPhBu6koKQEA3v1zK1NHND2t44vOXDKmYb8yThSP 7KHuutpcy9EGNwW4OARcks9qEgorBgEEAZdVAQUBAQdAMZUbpg1up2WOwPlQn3pP VaRMejyZnScmD7d5TRzHehwDAQgHiH4EGBYIACYCGwwWIQSx0r0Tdb7LeEz0+MTX PPY4xTwGvgUCaeCW1wUJDmqLbQAKCRDXPPY4xTwGvkTVAP9n2kDv5xU9OhPjJYZU HaP9HIZUFwuU2TD01b1QRcKCzgD/cSyStKMORI082CQeCvNdAC/yL+jxDgBIAOHD 0x1ZWwkACgkQUXIrCP5HRaJJWAD/aAFFRef/xB0bD+z1p1TFfhM3odtXzIvY+z/z A6JGUcwA/1O4sQX0jQziXOGrsT4VUfRsD0kWARB1ERyXgWNmGWoB =sHwU -----END PGP SIGNATURE-----