Re: Buffer overflow in the StringQuotedWord() function
William Bader <[email protected]> Thu, 22 Oct 2020 04:42:32 +0000
| Newsgroups | gmane.comp.type-setting.lout |
|---|---|
| Message-ID | <DB6PR0201MB24718E601BCCA47957D49920C41D0@DB6PR0201MB2471.eurprd02.prod.outlook.com> |
--_004_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_
Content-Type: multipart/alternative;
boundary="_000_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_"
--_000_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_
Content-Type: text/plain; charset="windows-1250"
Content-Transfer-Encoding: quoted-printable
>I can't see the bug descriptions without logging in?
I didn't have to log in.
I have the descriptions below, and I attached the example files that cause =
the problems (although the mailing list might strip it).
I am willing to look at it next week if no one else is already looking at i=
t.
With luck, it is just adding the tests in my previous email, confirming tha=
t it fixes the crashes, and using the docs distributed with lout as a regre=
ssion test.
Regards, William
CVE-2019-19918
https://lists.gnu.org/archive/html/lout-users/2019-12/msg00001.html
ERROR: AddressSanitizer: heap-buffer-overflow on address
0x6260000000ff at pc 0x0000004d9b84 bp 0x7fff16458220 sp 0x7fff16458218
WRITE of size 1 at 0x6260000000ff thread T0
#0 0x4d9b83 in srcnext /home/fcambus/lout-3.40/z02.c:381:26
#1 0x4d37b2 in LexGetToken /home/fcambus/lout-3.40/z02.c:491:15
#2 0x4f75fd in Parse /home/fcambus/lout-3.40/z06.c:819:7
#3 0x4ce4b5 in run /home/fcambus/lout-3.40/z01.c:898:9
#4 0x4c30f4 in main /home/fcambus/lout-3.40/z01.c:971:5
#5 0x7f11f51731e2 in __libc_start_main
/build/glibc-4WA41p/glibc-2.30/csu/../csu/libc-start.c:308:16
#6 0x41b45d in _start (/home/fcambus/lout-3.40/lout+0x41b45d)
0x6260000000ff is located 1 bytes to the left of 10243-byte region
[0x626000000100,0x626000002903)
allocated by thread T0 here:
#0 0x49335d in malloc (/home/fcambus/lout-3.40/lout+0x49335d)
#1 0x4d1c2d in LexPush /home/fcambus/lout-3.40/z02.c:240:29
CVE-2019-19917
https://lists.gnu.org/archive/html/lout-users/2019-12/msg00002.html
ERROR: AddressSanitizer: global-buffer-overflow on address
0x000001043820 at pc 0x000000683f48 bp 0x7ffed5cd8ad0 sp 0x7ffed5cd8ac8
WRITE of size 1 at 0x000001043820 thread T0
#0 0x683f47 in StringQuotedWord /home/fcambus/lout-3.40/z39.c:254:66
#1 0x689912 in WriteObject /home/fcambus/lout-3.40/z41.c:310:7
#2 0x68b320 in WriteClosure /home/fcambus/lout-3.40/z41.c:215:4
#3 0x689fb8 in WriteObject /home/fcambus/lout-3.40/z41.c:469:7
#4 0x6884a1 in AppendToFile /home/fcambus/lout-3.40/z41.c:688:3
#5 0x57b60f in CrossSequence /home/fcambus/lout-3.40/z10.c:891:2
#6 0x6172ed in Promote /home/fcambus/lout-3.40/z22.c:838:4
#7 0x5face4 in FlushGalley /home/fcambus/lout-3.40/z20.c:776:7
#8 0x5d5e23 in TransferEnd /home/fcambus/lout-3.40/z18.c:499:5
#9 0x4ce4e2 in run /home/fcambus/lout-3.40/z01.c:901:3
#10 0x4c30f4 in main /home/fcambus/lout-3.40/z01.c:971:5
#11 0x7f00c952b1e2 in __libc_start_main
/build/glibc-4WA41p/glibc-2.30/csu/../csu/libc-start.c:308:16
#12 0x41b45d in _start (/home/fcambus/lout-3.40/lout+0x41b45d)
0x000001043820 is located 0 bytes to the right of global variable 'buff'
defined in 'z39.c:248:20' (0x1043620) of size 512
SUMMARY: AddressSanitizer: global-buffer-overflow
________________________________
From: Oliver Bandel <[email protected]>
Sent: Wednesday, October 21, 2020 9:02 PM
To: Mat=ECj Cepl <[email protected]>
Cc: William Bader <[email protected]>; Frederic Cambus <fred@statdns=
.com>; [email protected] <[email protected]>
Subject: Re: Buffer overflow in the StringQuotedWord() function
Quoting Mat=ECj Cepl <[email protected]> (snt: 2020-10-20 17:20 +0200 CEST) (r=
cv: 2020-10-20 17:21 +0200 CEST):
> William Bader p=ED=9Ae v So 21. 12. 2019 v 11:59 +0000:
> > Is anyone still maintaining lout?
>
> That=92s the question, isn=92t it? We have in OpenSUSE still two
> opened CVEs (https://bugzilla.suse.com/1159713 and
> https://bugzilla.suse.com/1159714), Debian just removed lout
> from its archive (https://bugs.debian.org/972182).
[...]
I can't see the bug descriptions without logging in?
wtf.
And following the smash.suse.de-link, I got an error.
Ciao,
Oliver
--_000_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_
Content-Type: text/html; charset="windows-1250"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dwindows-1=
250">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
>I can't see the bug descriptions without logging in?</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
I didn't have to log in.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
I have the descriptions below, and I attached the example files that cause =
the problems (although the mailing list might strip it).</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
I am willing to look at it next week if no one else is already looking at i=
t.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
With luck, it is just adding the tests in my previous email, confirming tha=
t it fixes the crashes, and using the docs distributed with lout as a regre=
ssion test.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
Regards, William</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
CVE-2019-19918<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
<a href=3D"https://lists.gnu.org/archive/html/lout-users/2019-12/msg00001.h=
tml" id=3D"LPlnk308889">https://lists.gnu.org/archive/html/lout-users/2019-=
12/msg00001.html</a></div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
ERROR: AddressSanitizer: heap-buffer-overflow on address
<div>0x6260000000ff at pc 0x0000004d9b84 bp 0x7fff16458220 sp 0x7fff1645821=
8</div>
<div>WRITE of size 1 at 0x6260000000ff thread T0</div>
<div> #0 0x4d9b83 in srcnext /home/fcambus/lout-3.40/z02.c:381=
:26</div>
<div> #1 0x4d37b2 in LexGetToken /home/fcambus/lout-3.40/z02.c=
:491:15</div>
<div> #2 0x4f75fd in Parse /home/fcambus/lout-3.40/z06.c:819:7=
</div>
<div> #3 0x4ce4b5 in run /home/fcambus/lout-3.40/z01.c:898:9</=
div>
<div> #4 0x4c30f4 in main /home/fcambus/lout-3.40/z01.c:971:5<=
/div>
<div> #5 0x7f11f51731e2 in __libc_start_main </div>
<div>/build/glibc-4WA41p/glibc-2.30/csu/../csu/libc-start.c:308:16</div>
<div> #6 0x41b45d in _start (/home/fcambus/lout-3.40/lout+0x41=
b45d)</div>
<div>0x6260000000ff is located 1 bytes to the left of 10243-byte region<br>
</div>
<div>[0x626000000100,0x626000002903)</div>
<div>allocated by thread T0 here:</div>
<div> #0 0x49335d in malloc (/home/fcambus/lout-3.40/lout+0x49=
335d)</div>
<div> #1 0x4d1c2d in LexPush /home/fcambus/lout-3.40/z02.c:240=
:29</div>
<br>
CVE-2019-19917<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
<a href=3D"https://lists.gnu.org/archive/html/lout-users/2019-12/msg00002.h=
tml" id=3D"LPlnk829373">https://lists.gnu.org/archive/html/lout-users/2019-=
12/msg00002.html</a><br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
color: rgb(0, 0, 0);">
ERROR: AddressSanitizer: global-buffer-overflow on address
<div>0x000001043820 at pc 0x000000683f48 bp 0x7ffed5cd8ad0 sp 0x7ffed5cd8ac=
8</div>
<div>WRITE of size 1 at 0x000001043820 thread T0</div>
<div> #0 0x683f47 in StringQuotedWord /home/fcambus/lout-3.40/=
z39.c:254:66</div>
<div> #1 0x689912 in WriteObject /home/fcambus/lout-3.40/z41.c=
:310:7</div>
<div> #2 0x68b320 in WriteClosure /home/fcambus/lout-3.40/z41.=
c:215:4</div>
<div> #3 0x689fb8 in WriteObject /home/fcambus/lout-3.40/z41.c=
:469:7</div>
<div> #4 0x6884a1 in AppendToFile /home/fcambus/lout-3.40/z41.=
c:688:3</div>
<div> #5 0x57b60f in CrossSequence /home/fcambus/lout-3.40/z10=
.c:891:2</div>
<div> #6 0x6172ed in Promote /home/fcambus/lout-3.40/z22.c:838=
:4</div>
<div> #7 0x5face4 in FlushGalley /home/fcambus/lout-3.40/z20.c=
:776:7</div>
<div> #8 0x5d5e23 in TransferEnd /home/fcambus/lout-3.40/z18.c=
:499:5</div>
<div> #9 0x4ce4e2 in run /home/fcambus/lout-3.40/z01.c:901:3</=
div>
<div> #10 0x4c30f4 in main /home/fcambus/lout-3.40/z01.c:971:5=
</div>
<div> #11 0x7f00c952b1e2 in __libc_start_main </div>
<div>/build/glibc-4WA41p/glibc-2.30/csu/../csu/libc-start.c:308:16</div>
<div> #12 0x41b45d in _start (/home/fcambus/lout-3.40/lout+0x4=
1b45d)</div>
<div>0x000001043820 is located 0 bytes to the right of global variable 'buf=
f' </div>
<div>defined in 'z39.c:248:20' (0x1043620) of size 512</div>
SUMMARY: AddressSanitizer: global-buffer-overflow <br>
</div>
<div>
<div id=3D"appendonsend"></div>
<div style=3D"font-family:Calibri,Helvetica,sans-serif; font-size:12pt; col=
or:rgb(0,0,0)">
<br>
</div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" co=
lor=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Oliver Bandel <oli=
[email protected]><br>
<b>Sent:</b> Wednesday, October 21, 2020 9:02 PM<br>
<b>To:</b> Mat=ECj Cepl <[email protected]><br>
<b>Cc:</b> William Bader <[email protected]>; Frederic Cambus =
<[email protected]>; [email protected] <[email protected]&g=
t;<br>
<b>Subject:</b> Re: Buffer overflow in the StringQuotedWord() function</fon=
t>
<div> </div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt"=
>
<div class=3D"PlainText">Quoting Mat=ECj Cepl <[email protected]> (=
snt: 2020-10-20 17:20 +0200 CEST) (rcv: 2020-10-20 17:21 +0200 CEST):<br>
> William Bader p=ED=9Ae v So 21. 12. 2019 v 11:59 +0000:<br>
> > Is anyone still maintaining lout?<br>
> <br>
> That=92s the question, isn=92t it? We have in OpenSUSE still two <br>
> opened CVEs (<a href=3D""></a>https://bugzilla.suse.com/1159713 and<br=
>
> <a href=3D"https://bugzilla.suse.com/1159714">https://bugzilla.suse.co=
m/1159714</a>), Debian just removed lout
<br>
> from its archive (<a href=3D"https://bugs.debian.org/972182">https://b=
ugs.debian.org/972182</a>).<br>
[...]<br>
<br>
I can't see the bug descriptions without logging in?<br>
wtf.<br>
<br>
And following the smash.suse.de-link, I got an error.<br>
<br>
<br>
Ciao,<br>
Oliver<br>
</div>
</span></font></div>
</div>
</body>
</html>
--_000_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_--
--_004_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_
Content-Type: application/x-bzip; name="lout-cve.tar.bz2"
Content-Description: lout-cve.tar.bz2
Content-Disposition: attachment; filename="lout-cve.tar.bz2"; size=1787;
creation-date="Thu, 22 Oct 2020 04:32:34 GMT";
modification-date="Thu, 22 Oct 2020 04:32:55 GMT"
Content-Transfer-Encoding: base64
QlpoOTFBWSZTWYbUyr0AFzt/rP+SAsFMb3/9///9oH/v//pAACAAAAQACGAKXz5VUgSpG3cyQiUq
qJFKAUoQaSI9QAADQAAAAABoAAAABFMSNlHqPUAA0AAAAAAAAAAA40NA0aZGmjTIDEwQAA0BoDTI
DAmQcaGgaNMjTRpkBiYIAAaA0BpkBgTIE1SJEqfmoGqeFNDxIaBtRkaaep6QZDQNGgADTQFKSICT
FMnqbUNE9RkDTSNPSGmEYjAExPGqbUej1P3vle49z17sr+fFRwvT9bGHp9P1c4Li9ypCyx4U1TUT
ZlK2g+R9MNMisshmIkv2qjzUrixT2OUU5BOc+ZZCSf1sAHFQe3kFV4n2nWD99/C+e1f4sv/r4ml6
LgtGFxvnW0bWx/Z4H4LoOt4BdKybZSwyulpp+Z33cuu3uVg/8fPfTCu2woHOyRcIYmXNqWnRqI8b
zuK3Vdrhqm11OK7jK+Z1tP87scXzXc1Gzm43msjQy6W95Hy3K2c2nDTmsdGMdV53cuUhyLw2VTrI
8lDRcSVgNpW0rSNRqNlbJYY2bNLArCuT9p6mNGj7ZqZNp2zJtWVlpbWRoYO21bjjn/VUtNni05sb
NHqOhk3Ok4zeZNhxvC1cbVxsuNluOFic/xIrZzOjg2NHQ5zJvOk4zesrjdFxsuFlwGDsuFyHs5pj
m6NNmjoc5k3nScZvNmplzY63NjmxzcLTKuTJeAJ6q9p6Xpep7j1Pdc3i+DM3em+k997z3HUntA/9
ege8t5Fy/JUnQfDPgvgHvWWWXuseljRo981MW1wsWzSxjbFaq2xn03m9tyvdetWV+Z4M/Dtfat6f
gd12WmrVhaNLGYzBsOx8dvbWljYzYxNMY3Q00YYYsrKxZVi4aYxaW1yYsVkNraxYscMY4pwZVhlT
I3VwcVaZVi0cqyytZX2dF+Xyd7t7vU3freZwE/HceCCRAxGBEFBVwE00AiYGHyygD4FjNSqBzrmi
SJjBIddeIV33Dg5Pud7bmdvY7e0zbucePf3djr36MdW98ZiHOQoiACEiFMosYqAcQgMZIyaYFGA0
AtIDsEJFBhE+v67co4tOTYTTKo3SMaZVGNNSjTKoyYqNSHkZSLgZTHtGDDCMMYaSNL3WDDFppi1G
WLGTMGDGjGGmGlpUddwvoPLu22xq1lppqpqZGTFkxay0tN7bW29222NWstNNC1MqxZMWTWNTVt/B
Fev3+VzQ6mLTBhgwyMpG0K6mwwwYbDSyxMnQ0MMF+wK2q+dqqWmxP1WJqYmT9CFMdFpFeU/ag6Si
5J0nsttRaaafhabbm226ttttuJ+eUbqjtXRixi4amND9j5VwxYriqNS77u2BMKNztXJWTJTR5DQy
ZVk0NUywsm9zsmMMMYxjDDDDDDJkyZWLFixYsWGGGGMZMmMYxllllgwYMGWWWWGGGGZmXfavEwK3
v9LLkfG753TanWYzJmVu3rhcOGltarS0atLS4vAuOW7a3W1ttNuPW+91vC63F0ZZMsMcmWTLDXAk
0u/cfUnxO86NPC6nlvovfmJK7t8c+FgV+e/ycL1ErxvpuZTxPlr3owK63ZZQdQTvX1Z/2UX6Yjsv
ieqUXO0x8l8anodH3ArtuN1vrvyW1/uJ4WIanhJcJVefqvQ+i4SVcLscJ4u9dpZYMvdBi0WWDLru
DS2plky3LZWjZkxYyxuHLpd6dUotG6K9DTlV2vK9Yxk+Cx5LyO9dTmx1OTmRwlYhlWKyXZhaYh/x
0fzeKxmpoZa1ZlrNBjK01MmTLLTLWbc5Vjk1JXlObZ9C9DrZwKO6+aFc71WHc9t5FwoeJ4V2OUl/
yV4rJ687rtZMZFHHbdIV43VasZYrDB7lwvdsMhWErsCyeR7L4rlfC3n6Z6vAt7da+8Fk8qHmKcTt
SHfskvYqmqfLXNQ7l5bLkFcHv3lMorpp9Fu4N7sQ8HavI5ut6Cj4F4owkySu6+oJ32yR1e2XkOFx
KYhsfCo+CuK2irgfULeUxGKxMhzvv1S3Ado5FWoq3rktrLaRgV6A0kYjhGnALd72ANlje3oGyKcX
xR7FyXG41B7CRvdD2rFTg6vPfEMmQrlUHmUcF576fsn/97d4eRJ79y9hR8+I7HjiPA081eRuVcWn
Nux1tsVZWDDVhXsijhd2+kU9ePO9q4yVd6TNriaauaMXnelvc7zOF22WW1ym0UY1U8dff6OjLseq
7HDhzbu+xXheNfJGWU84sWplMsvtOvF8mUI4LjGJVlXO7nMppp5PYvK9sd95lxCt3K7RRvJV9Xtc
L8T13msQw6W5R/buSfHetq4XyIp4rzPO/o8H4Ce89nQo5XxnY4avQuIjz3ZfzkYsqrGFmdglTAmU
lT4fZ4LRPOv/i7kinChIQ2plXoA=
--_004_DB6PR0201MB24718E601BCCA47957D49920C41D0DB6PR0201MB2471_--