#1513 closed defect (fixed)
Security fix for yet another nasm buffer overflow.
| Reported by: | Owned by: | ||
|---|---|---|---|
| Priority: | highest | Milestone: | |
| Component: | BOOK | Version: | b-6.1-pre1 |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Nasm-0.98.39 fixed the CAN-2004-1287 buffer overflow. The following patch taken from CVS addresses CAN-2005-1194. Vulnerability is probably low.
I've just submitted this with the proper headers to patches as
nasm-0.98.39-security_fix-1.patch. Ken
--- nasm-0.98.39/output/outieee.c.orig 2005-01-15 22:16:08.000000000 +0000 +++ nasm-0.98.39/output/outieee.c 2005-08-08 22:12:46.000000000 +0100 @@ -1120,7 +1120,7 @@
va_list ap;
va_start(ap, format);
- vsprintf(buffer, format, ap);
+ vsnprintf(buffer, sizeof(buffer), format, ap);
l = strlen(buffer); for (i = 0; i < l; i++)
if ((buffer[i] & 0xff) > 31)
Change History (6)
comment:1 by , 21 years ago
| Milestone: | future → 6.1 |
|---|---|
| Owner: | changed from to |
| Priority: | high → highest |
| rep_platform: | PC → All |
comment:2 by , 21 years ago
| Status: | new → assigned |
|---|
comment:3 by , 21 years ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Added the patch to the NASM instructions.
Keeping the bug open until Bruce merges the changes into the 6.1 branch (r4896)
comment:4 by , 21 years ago
| Status: | new → assigned |
|---|
comment:5 by , 21 years ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Merged changes from nasm into 6.1-pre2.

I'll knock this out right now and we can get it into 6.1