Bug 1325786 - date --date aborts when passed incorrectly quoted string, glibc:"Double free or corruption".
Summary: date --date aborts when passed incorrectly quoted string, glibc:"Double free ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: coreutils
Version: 7.2
Hardware: Unspecified
OS: Unspecified
unspecified
low
Target Milestone: rc
: ---
Assignee: Ondrej Vasik
QA Contact: Jakub Prokes
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-04-11 08:11 UTC by Donald Douwsma
Modified: 2016-11-04 07:40 UTC (History)
2 users (show)

Fixed In Version: coreutils-8.22-17.el7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-04 07:40:24 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2497 0 normal SHIPPED_LIVE coreutils bug fix update 2016-11-03 14:11:50 UTC

Description Donald Douwsma 2016-04-11 08:11:25 UTC
Description of problem:

date core dumps when passed an incorrectly quoted string.

# date --date='TZ="IST" 11:30PM"'
                               ^
  *** Error in `date': double free or corruption (out): 0x00007ffcd83e9700 ***
  ...

(gdb) bt
#0  0x00007f7c1cdec5f7 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
#1  0x00007f7c1cdedce8 in __GI_abort () at abort.c:90
#2  0x00007f7c1ce2c317 in __libc_message (do_abort=do_abort@entry=2, fmt=fmt@entry=0x7f7c1cf35988 "*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/unix/sysv/linux/libc_fatal.c:196
#3  0x00007f7c1ce33fe1 in malloc_printerr (ar_ptr=0x7f7c1d171760 <main_arena>, ptr=<optimized out>, str=0x7f7c1cf35a68 "double free or corruption (out)", action=3) at malloc.c:5013
#4  _int_free (av=0x7f7c1d171760 <main_arena>, p=<optimized out>, have_lock=0) at malloc.c:3835
#5  0x00000000004065e0 in parse_datetime (result=result@entry=0x7ffd0fcbf100, p=<optimized out>, p@entry=0x7ffd0fcc0672 "TZ=\"IST\" 11:30PM\"B", now=<optimized out>, now@entry=0x0)
    at lib/parse-datetime.y:1307
#6  0x0000000000402245 in main (argc=2, argv=0x7ffd0fcbf2c8) at src/date.c:515

Version-Release number of selected component: coreutils-8.22-15.el7.x86_64
How reproducible: always

Comment 1 Ondrej Vasik 2016-04-14 14:13:10 UTC
http://git.savannah.gnu.org/cgit/gnulib.git/commit/lib/parse-datetime.y?id=a10acfb1d2118f9a180181d3fed5399dbbe1df3c fixes this and similar issues. Reproducer and fix confirmed.

Comment 9 errata-xmlrpc 2016-11-04 07:40:24 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2497.html


Note You need to log in before you can comment on or make changes to this bug.