Re: Buffer overflow in the StringQuotedWord() function

William Bader <[email protected]> Fri, 23 Oct 2020 04:19:54 +0000
Newsgroups gmane.comp.type-setting.lout
Message-ID <DB6PR0201MB2471573580B639A80E887A67C41A0@DB6PR0201MB2471.eurprd02.prod.outlook.com>
--_000_DB6PR0201MB2471573580B639A80E887A67C41A0DB6PR0201MB2471_
Content-Type: text/plain; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

>with test02 not.

valgrind also didn't always catch one of them.
I saw them both only by building with
TRACING =3D -g -fno-omit-frame-pointer -fsanitize=3Daddress
COPTS  =3D -ansi -pedantic -Wall -O1
plus I added COPTS and TRACING them to the lout link line
$(CC) -o lout $(COPTS) $(TRACING) $(OBJS) $(ZLIB) -lm
I used Fedora 31 Linux on x86_64 with Fedora's gcc 9.3.1

>I could create a repo for lout at GitLab.

If you make it, I can post my other big patch file as an issue. It fixes a =
crash on pages with lots of nested boxes, adds support for PDF images when =
generating postscript, fixes an invalid access on fonts with a lot of kerne=
d glyphs, and scales images more accurately.

Regards,
William

________________________________
From: Oliver Bandel <[email protected]>
Sent: Thursday, October 22, 2020 9:20 PM
To: Mat=ECj Cepl <[email protected]>
Cc: William Bader <[email protected]>; Frederic Cambus <fred@statdns=
.com>; [email protected] <[email protected]>
Subject: Re: Buffer overflow in the StringQuotedWord() function

Quoting  Mat=ECj Cepl <[email protected]> (snt: 2020-10-22 07:58 +0200 CEST) (r=
cv: 2020-10-22 07:58 +0200 CEST):
> Oliver Bandel p=ED=B9e v =C8t 22. 10. 2020 v 03:02 +0200:
> > I can't see the bug descriptions without logging in?
> > wtf.
>
> I am sorry about that. These are
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19918 and
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19917
> , and both come from this list. I hope that's readable.
[...]

With test01 I get a segfault,
with test02 not.

I will try Williams Patches soon.

And if no one else would like to do it,
I could create a repo for lout at GitLab.

Ciao,
  Oliver

--_000_DB6PR0201MB2471573580B639A80E887A67C41A0DB6PR0201MB2471_
Content-Type: text/html; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
2">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
&gt;with test02 not.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
valgrind also didn't always catch one of them.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
I saw them both only by building with</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
TRACING =3D -g -fno-omit-frame-pointer -fsanitize=3Daddress</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
COPTS &nbsp;=3D -ansi -pedantic -Wall -O1<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
plus I added COPTS and TRACING them to the lout link line</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
$(CC) -o lout $(COPTS) $(TRACING) $(OBJS) $(ZLIB) -lm<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
I used Fedora 31 Linux on&nbsp;x86_64 with Fedora's gcc&nbsp;9.3.1</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
&gt;I could create a repo for lout at GitLab.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
If you make it, I can post my other big patch file as an issue. It fixes a =
crash on pages with lots of nested boxes, adds support for PDF images when =
generating postscript, fixes an invalid access on fonts with a lot of kerne=
d glyphs, and scales images more
 accurately.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
Regards,</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
William</div>
<div>
<div id=3D"appendonsend"></div>
<div style=3D"font-family:Calibri,Helvetica,sans-serif; font-size:12pt; col=
or:rgb(0,0,0)">
<br>
</div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" co=
lor=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Oliver Bandel &lt;oli=
[email protected]&gt;<br>
<b>Sent:</b> Thursday, October 22, 2020 9:20 PM<br>
<b>To:</b> Mat=ECj Cepl &lt;[email protected]&gt;<br>
<b>Cc:</b> William Bader &lt;[email protected]&gt;; Frederic Cambus =
&lt;[email protected]&gt;; [email protected] &lt;[email protected]&g=
t;<br>
<b>Subject:</b> Re: Buffer overflow in the StringQuotedWord() function</fon=
t>
<div>&nbsp;</div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt"=
>
<div class=3D"PlainText">Quoting&nbsp; Mat=ECj Cepl &lt;[email protected]&gt; (=
snt: 2020-10-22 07:58 +0200 CEST) (rcv: 2020-10-22 07:58 +0200 CEST):<br>
&gt; Oliver Bandel p=ED=B9e v =C8t 22. 10. 2020 v 03:02 +0200:<br>
&gt; &gt; I can't see the bug descriptions without logging in?<br>
&gt; &gt; wtf.<br>
&gt; <br>
&gt; I am sorry about that. These are <br>
&gt; <a href=3D"http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19=
918">http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19918</a> and
<br>
&gt; <a href=3D"http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19=
917">http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2019-19917</a>
<br>
&gt; , and both come from this list. I hope that's readable.<br>
[...]<br>
<br>
With test01 I get a segfault,<br>
with test02 not.<br>
<br>
I will try Williams Patches soon.<br>
<br>
And if no one else would like to do it,<br>
I could create a repo for lout at GitLab.<br>
<br>
Ciao,<br>
&nbsp; Oliver<br>
</div>
</span></font></div>
</div>
</body>
</html>

--_000_DB6PR0201MB2471573580B639A80E887A67C41A0DB6PR0201MB2471_--