Opened 21 years ago

Closed 21 years ago

Last modified 18 years ago

#1513 closed defect (fixed)

Security fix for yet another nasm buffer overflow.

Reported by: ken@… Owned by: bdubbs@…
Priority: highest Milestone:
Component: BOOK Version: b-6.1-pre1
Severity: medium Keywords:
Cc:

Description

Nasm-0.98.39 fixed the CAN-2004-1287 buffer overflow. The following patch taken from CVS addresses CAN-2005-1194. Vulnerability is probably low.

I've just submitted this with the proper headers to patches as

nasm-0.98.39-security_fix-1.patch. Ken

--- nasm-0.98.39/output/outieee.c.orig 2005-01-15 22:16:08.000000000 +0000 +++ nasm-0.98.39/output/outieee.c 2005-08-08 22:12:46.000000000 +0100 @@ -1120,7 +1120,7 @@

va_list ap;

va_start(ap, format);

  • vsprintf(buffer, format, ap);

+ vsnprintf(buffer, sizeof(buffer), format, ap);

l = strlen(buffer); for (i = 0; i < l; i++)

if ((buffer[i] & 0xff) > 31)

Change History (6)

comment:1 by LFS-User@…, 21 years ago

Milestone: future → 6.1
Owner: changed from blfs-book@… to Randy McMurchy
Priority: high → highest
rep_platform: PC → All

I'll knock this out right now and we can get it into 6.1

comment:2 by LFS-User@…, 21 years ago

Status: new → assigned

comment:3 by LFS-User@…, 21 years ago

Owner: changed from Randy McMurchy to bdubbs@…
Status: assigned → new

Added the patch to the NASM instructions.

Keeping the bug open until Bruce merges the changes into the 6.1 branch (r4896)

comment:4 by LFS-User@…, 21 years ago

Status: new → assigned

comment:5 by bdubbs@…, 21 years ago

Resolution: → fixed
Status: assigned → closed

Merged changes from nasm into 6.1-pre2.

comment:6 by (none), 18 years ago

Milestone: 6.1

Milestone 6.1 deleted

Note: See TracTickets for help on using tickets.