Bug#1024735: klibc-utils: klibc sh segfault on invalid substitutions

2022-12-06 Thread Christoph Anton Mitterer
Just for the records, meanwhile I've also opened a proper ticket about
this over at BusyBox regarding the same bug in their sh at:

https://bugs.busybox.net/show_bug.cgi?id=15171



Bug#1024735: klibc-utils: klibc sh segfault on invalid substitutions

2022-11-23 Thread Christoph Anton Mitterer
Package: klibc-utils
Version: 2.0.11-1
Severity: normal
Tags: upstream


Hey there.

There’s a bug in ash-bashed shells, including the one shipped with
klibc.

The original variant is described here (for dash):
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1024635
respectively
https://lore.kernel.org/dash/b2e298215b3d51d8284296484caa138faddaa0e4.ca...@scientia.org/


Apparently BusyBox’ sh (also ash based) doesn't segfault on the
example I've found above.

But Harald van Dijk was able to create an example where BusyBox’ sh
segfaults, too, reported:
http://lists.busybox.net/pipermail/busybox/2022-November/090036.html



klibc’s sh segfaults in BOTH cases.

I'll also post this to the upstream mailing list and set it as
forwarded here afterwards.

Thanks,
Chris.