Bug 1644196 - There is abort in libwebm caused by libwebm::Webm2Pes::InitWebmParser() which will lead to dos attack.
Summary: There is abort in libwebm caused by libwebm::Webm2Pes::InitWebmParser() which...
Status: CLOSED NOTABUG
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-10-30 08:07 UTC by shuitao gan
Modified: 2018-11-13 20:33 UTC (History)
1 user (show)

(edit)
Clone Of:
(edit)
Last Closed: 2018-11-13 20:26:41 UTC


Attachments (Terms of Use)
./webm2pes POC0 /dev/null (4.55 KB, application/octet-stream)
2018-10-30 08:07 UTC, shuitao gan
no flags Details

Description shuitao gan 2018-10-30 08:07:49 UTC
Created attachment 1498865 [details]
./webm2pes POC0 /dev/null

version: latest version
Summary: 

There is abort in libwebm caused by libwebm::Webm2Pes::InitWebmParser() which will lead to dos attack. 

Description:

$./webm2pes POC0 /dev/null

terminate called after throwing an instance of 'std::logic_error'
  what():  basic_string::_M_construct null not valid
Aborted (core dumped)

Program received signal SIGABRT, Aborted.
0x00007ffff6b79267 in __GI_raise (sig=sig@entry=6)
    at ../sysdeps/unix/sysv/linux/raise.c:55
55	../sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) bt
#0  0x00007ffff6b79267 in __GI_raise (sig=sig@entry=6)
    at ../sysdeps/unix/sysv/linux/raise.c:55
#1  0x00007ffff6b7aeca in __GI_abort () at abort.c:89
#2  0x00007ffff7ae6b7d in __gnu_cxx::__verbose_terminate_handler() ()
   from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#3  0x00007ffff7ae49c6 in ?? () from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#4  0x00007ffff7ae4a11 in std::terminate() ()
   from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#5  0x00007ffff7ae4c29 in __cxa_throw ()
   from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#6  0x00007ffff7b0d50f in std::__throw_logic_error(char const*) ()
   from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#7  0x00007ffff7b78f94 in void std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> 
>::_M_construct<char const*>(char const*, char const*, std::forward_iterator_tag) () from /usr/lib/x86_64-linux-gnu/libstdc+
+.so.6
#8  0x00007ffff7b7914c in std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >::basic_string(char 
const*, std::allocator<char> const&) () from /usr/lib/x86_64-linux-gnu/libstdc++.so.6
#9  0x00000000004a3964 in libwebm::Webm2Pes::InitWebmParser() ()
#10 0x00000000004a198f in libwebm::Webm2Pes::ConvertToFile() ()
#11 0x000000000048a701 in main ()

Comment 1 Pedro Sampaio 2018-11-13 20:26:41 UTC
This is not shipped in any Red Hat products. Closing.


Note You need to log in before you can comment on or make changes to this bug.