Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > gnu.utils.bug > #2240

Re: Vulnerability Report on Sharutils 4.15.2

From Petr Pisar <ppisar@redhat.com>
Newsgroups gnu.utils.bug
Subject Re: Vulnerability Report on Sharutils 4.15.2
Date 2018-04-10 14:54 +0000
Message-ID <mailman.11974.1523372567.27995.bug-gnu-utils@gnu.org> (permalink)
References (1 earlier) <20180325175147.GA13587@eldamar.local> <CAFkjv+vMm9SB+U04_97D+To9DUaOBS2O6uLBxM1=PsPYGdn8qg@mail.gmail.com> <20180326044616.f4aouw6a2k5px4jq@lorien.valinor.li> <CAFkjv+vZgV6zbrhnLQDpJETZjMyajo05=r+wtqZ6BvtgjV7=xg@mail.gmail.com> <20180406042611.GA3637@eldamar.local>

Show all headers | View raw


On 2018-04-06, Salvatore Bonaccorso <carnil@debian.org> wrote:
> AFAICT for this issue still no proposed fix is available for the
> issues raised in
> https://lists.gnu.org/archive/html/bug-gnu-utils/2018-02/msg00003.html,

Well, I cannot reproduce it. Maybe the attachent with the reproducer is
wrong. The message reads 2.fuzz, but the attachent contains four
SIGSEGV*.fuzz files. Runnning unshar on any of them results in:

sh: line 14386: warning: here-document at line 37 delimited by end-of-file (wanted `_EOF_')
sh: line 14387: syntax error: unexpected end of file

(the line numbers differ) and valgrdind does not show any issue in the
unshar process.

-- Petr

Back to gnu.utils.bug | Previous | Next | Find similar


Thread

Re: Vulnerability Report on Sharutils 4.15.2 Petr Pisar <ppisar@redhat.com> - 2018-04-10 14:54 +0000

csiph-web