Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 652557 - Tests 253 and 255 FAIL: stack smashing detected
Tests 253 and 255 FAIL: stack smashing detected
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: curl (Show other bugs)
5.6
i386 Unspecified
high Severity high
: rc
: ---
Assigned To: Kamil Dudka
Dalibor Pospíšil
: Patch
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2010-11-12 03:15 EST by Miroslav Vadkerti
Modified: 2012-10-10 05:42 EDT (History)
2 users (show)

See Also:
Fixed In Version: curl-7.15.5-14.el5
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-02-21 01:15:01 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
proposed fix (562 bytes, patch)
2010-11-15 13:56 EST, Kamil Dudka
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2012:0241 normal SHIPPED_LIVE curl bug fix and enhancement update 2012-02-20 10:07:27 EST

  None (edit)
Description Miroslav Vadkerti 2010-11-12 03:15:06 EST
Description of problem:
Test 253 comming from upstream test suite fails:
../src/curl --output log/curl253.out  --include -v --trace-time -g "ftp://[::1]:8996/" -P - >>log/stdout253 2>>log/stderr253
*** stack smashing detected ***: /tmp/tmp.GWXLh29666/BUILD/curl-7.15.5/src/.libs/lt-curl terminated
sh: line 1:  4816 Aborted                 ../src/curl --output log/curl253.out --include -v --trace-time -g "ftp://[::1]:8996/" -P - >> log/stdout253 2>> log/stderr253

Please note that I use MALLOC_PERTURB_:
echo "export MALLOC_PERTURB_=$(($RANDOM % 255 + 1))" >> /etc/profile

Version-Release number of selected component (if applicable):
curl-7.15.5-9.el5

How reproducible:
100%

Steps to Reproduce:
1. run testsuite
  
Actual results:
stack smashing

Expected results:
no stack smashing

Additional info:
Comment 2 Kamil Dudka 2010-11-15 13:56:44 EST
Created attachment 460606 [details]
proposed fix

upstream commit: https://github.com/bagder/curl/commit/8ec1bfe
Comment 3 RHEL Product and Program Management 2011-05-31 10:10:34 EDT
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated in the
current release, Red Hat is unfortunately unable to address this
request at this time. Red Hat invites you to ask your support
representative to propose this request, if appropriate and relevant,
in the next release of Red Hat Enterprise Linux.
Comment 8 Kamil Dudka 2011-09-09 08:45:21 EDT
I got the crash above with 32bit libcurl in mock.  With the patched version of libcurl, it does not happen any more.  On x86_64, I was not successful in reproducing the crash with any version.
Comment 12 errata-xmlrpc 2012-02-21 01:15:01 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2012-0241.html

Note You need to log in before you can comment on or make changes to this bug.