oss-sec mailing list archives
Re: catdoc: out of bounds heap read and nullpointer / segfault
From: Agostino Sarubbo <ago () gentoo org>
Date: Sun, 25 Nov 2018 13:09:12 +0100
On domenica 25 novembre 2018 09:57:37 CET Hanno Böck wrote:
I reported two memory safety bugs in the command line tool catdoc. However the mails to the developer bounced. The first is an out of bounds heap read, to detect it catdoc needs to be compiled with address sanitizer (test it with -fsanitize=address in CFLAGS). The second is a null pointer and will just crash catdoc.
Hi Hanno, something about catdoc was already reported time ago: https://marc.info/?l=oss-security&m=142627461816744&w=2 I don't know atm if your findings are duplicate or not. -- Agostino Sarubbo Gentoo Linux Developer
Current thread:
- catdoc: out of bounds heap read and nullpointer / segfault Hanno Böck (Nov 25)
- Re: catdoc: out of bounds heap read and nullpointer / segfault Agostino Sarubbo (Nov 25)
- Re: catdoc: out of bounds heap read and nullpointer / segfault Hanno Böck (Nov 25)
- Re: catdoc: out of bounds heap read and nullpointer / segfault Agostino Sarubbo (Nov 25)