Bug 1340757
Summary: | [abrt] off-by-one error in curl's URL globbing causes SIGSEGV | ||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Romain Coltel <rcoltel> | ||||||||||||||||||||||||||||
Component: | curl | Assignee: | Kamil Dudka <kdudka> | ||||||||||||||||||||||||||||
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||||||||||||||||||||||||
Severity: | unspecified | Docs Contact: | |||||||||||||||||||||||||||||
Priority: | unspecified | ||||||||||||||||||||||||||||||
Version: | 23 | CC: | kdudka, paul | ||||||||||||||||||||||||||||
Target Milestone: | --- | Keywords: | Patch | ||||||||||||||||||||||||||||
Target Release: | --- | ||||||||||||||||||||||||||||||
Hardware: | x86_64 | ||||||||||||||||||||||||||||||
OS: | Unspecified | ||||||||||||||||||||||||||||||
URL: | https://retrace.fedoraproject.org/faf/reports/bthash/9c72ad7fc4b8fd61e509c1c2acbdda80e8f16590 | ||||||||||||||||||||||||||||||
Whiteboard: | abrt_hash:ae8d6b99da752ac0e48165140548550142d0b984;VARIANT_ID=workstation; | ||||||||||||||||||||||||||||||
Fixed In Version: | curl-7.49.1-2.fc25 curl-7.43.0-7.fc23 curl-7.47.1-5.fc24 | Doc Type: | If docs needed, set a value | ||||||||||||||||||||||||||||
Doc Text: | Story Points: | --- | |||||||||||||||||||||||||||||
Clone Of: | Environment: | ||||||||||||||||||||||||||||||
Last Closed: | 2016-06-07 01:23:35 UTC | Type: | --- | ||||||||||||||||||||||||||||
Regression: | --- | Mount Type: | --- | ||||||||||||||||||||||||||||
Documentation: | --- | CRM: | |||||||||||||||||||||||||||||
Verified Versions: | Category: | --- | |||||||||||||||||||||||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||||||||||||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||||||||||||||||||
Embargoed: | |||||||||||||||||||||||||||||||
Attachments: |
|
Description
Romain Coltel
2016-05-30 08:57:21 UTC
Created attachment 1162717 [details]
File: backtrace
Created attachment 1162718 [details]
File: cgroup
Created attachment 1162719 [details]
File: core_backtrace
Created attachment 1162720 [details]
File: dso_list
Created attachment 1162721 [details]
File: environ
Created attachment 1162722 [details]
File: exploitable
Created attachment 1162723 [details]
File: limits
Created attachment 1162724 [details]
File: maps
Created attachment 1162725 [details]
File: mountinfo
Created attachment 1162726 [details]
File: namespaces
Created attachment 1162727 [details]
File: open_fds
Created attachment 1162728 [details]
File: proc_pid_status
Created attachment 1162729 [details]
File: var_log_messages
Thank you for reporting the bug! It looks like an obvious off-by-one error: --- a/src/tool_urlglob.c +++ b/src/tool_urlglob.c @@ -400,9 +400,9 @@ static CURLcode glob_parse(URLGlob *glob, char *pattern, break; } } - if(++glob->size > GLOB_PATTERN_NUM) + if(++glob->size >= GLOB_PATTERN_NUM) return GLOBERROR("too many globs", pos, CURLE_URL_MALFORMAT); } return res; } There is a risk that the issue has impact on security. Please do not share it publicly until it is properly investigated. I will notify curl upstream about this. upstream commit: https://github.com/curl/curl/commit/584d0121 fixed in curl-7.49.1-2.fc25 curl-7.43.0-7.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2016-828d573a0f curl-7.47.1-5.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2016-2b2eafcf2f curl-7.47.1-5.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-2b2eafcf2f curl-7.43.0-7.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-828d573a0f curl-7.43.0-7.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report. curl-7.47.1-5.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report. |