Your message dated Wed, 18 Aug 2021 18:05:42 +0000
with message-id <[email protected]>
and subject line Bug#992413: fixed in nickle 2.91
has caused the Debian Bug report #992413,
regarding nickle: potential buffer overflow vulnerability in edit.c
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
992413: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=992413
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: nickle
Version: 2.90
Severity: normal
X-Debbugs-Cc: [email protected]
Dear Maintainer,
I found a potential buffer overflow vulnerability in edit.c.
At line 30, the program reads the value of 'editor' from an environment
variable.
Since size of 'buf' is fixed to 1024, if a malicious attack puts a large string
to 'editor',
it may cause stack buffer overflow at line 34 which leads to buggy behavior.
------------------------------------------------
30 if (!(editor = getenv ("EDITOR")))
31 editor = DEFAULT_EDITOR;
32 if (!file_name)
33 file_name = "";
34 (void) sprintf (buf, "%s %s", editor, file_name);
------------------------------------------------
Thank you.
-- System Information:
Debian Release: 11.0
APT prefers stable
APT policy: (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 5.10.16.3-microsoft-standard-WSL2 (SMP w/8 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: unable to detect
Versions of packages nickle depends on:
ii libc6 2.31-13
ii libreadline8 8.1-1
nickle recommends no packages.
nickle suggests no packages.
--- End Message ---
--- Begin Message ---
Source: nickle
Source-Version: 2.91
Done: Keith Packard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
nickle, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Keith Packard <[email protected]> (supplier of updated nickle package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 18 Aug 2021 10:01:45 -0700
Source: nickle
Architecture: source
Version: 2.91
Distribution: unstable
Urgency: medium
Maintainer: Keith Packard <[email protected]>
Changed-By: Keith Packard <[email protected]>
Closes: 992413
Changes:
nickle (2.91) unstable; urgency=medium
.
* Make randint produce evenly distributed values
* Use asprintf in Command::edit to avoid buffer overflow. Closes: #992413.
Checksums-Sha1:
02eabbf984de8a1d16eaf298b672ce454c9955db 1501 nickle_2.91.dsc
6f307eab922d75ad19c339ff6ce84a8b800b10f7 2178572 nickle_2.91.tar.xz
5be2ef0ba0b0b7a7b9379ba7593c2c29168b1688 7541 nickle_2.91_amd64.buildinfo
Checksums-Sha256:
497cdc5b1196e034892a7de74f4289a8ce35732c16b958fec2610cbd08a679c7 1501
nickle_2.91.dsc
a27a063d4cb93701d2d05a5fb2895b51b28fa7a2b32463a829496fb5f63833b6 2178572
nickle_2.91.tar.xz
ce9adf7007daa089f8cfff541c4b53fdea5299cc8ea718da9c701ad75316111c 7541
nickle_2.91_amd64.buildinfo
Files:
a0229f7b0d65473f4a687f51c3641522 1501 interpreters optional nickle_2.91.dsc
6bf883b8533e684ca1a7f0dec09477f6 2178572 interpreters optional
nickle_2.91.tar.xz
44af1d1edd8fd493bc2855b84bf69c86 7541 interpreters optional
nickle_2.91_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEw4O3eCVWE9/bQJ2R2yIaaQAAABEFAmEdSR4ACgkQ2yIaaQAA
ABGWmQ/+I4ERtmgpvnQz2ePEfQqLzOAUc/Cjx46fxPQ/f8jzH1XFvW58S7y88RUW
5ws4U+0qKXwtlgNDEKE0GE35bCRoIGAE/GDPxmDieulhLyh89+Pr4FTbMPbRL+K4
V0RtWv86Pvnu6X28pLX+qEyjLFiL5RaPAbLjPQMjJoZUzsjXrVGBIKmKgnqNXRcY
pjB6RWkgPdPcPwb+s7VeEqEgEyJcjbwcbyW08iO/4HnwbUmXU3GgQXIAUsMhE5mj
K39LA6t4zn9MXuSFtLCZs7F/W+Qo5qgq3og9Dc/ci/sS5i5MENfzhFqOBf0B3R4k
3n9QqdLEUpmlBptSFHKs1Exhj7mquiExE7FjmyWrqJiEdEq5b7RtPE9U+VDGQ5xE
BStOyuhegfnhKtia/TMu612NmihQf23NU5Xo8t/mkAEGNLq0EwaySNqZ6z2eOq3h
uGlgXU3mOBCE3o/bw2768Nq2TkPQ7pjKRjRrNCUdVY1vPhxE3aYi2mH+JB4EdE8T
iUKYx6LqRp86fuUJtgtlQ/yJSa3+9tqr725vq98a6ndY4BMayNKMU2xU13TWDv0w
md4koUz77xN9vgjkrD2euSGAczklGmlF2NmB3MryLZp9bLmfAeJkoMDZCjCQBBsH
WVdmS7+9WtyX38OcmILaoNbwBMi8TsJ7JcrVRi01HjjTQ6JEK20=
=ncBx
-----END PGP SIGNATURE-----
--- End Message ---