Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Re: Zsh - Multiple DoS Vulnerabilities
- X-seq: zsh-workers 44291
- From: Oliver Kiddle <okiddle@xxxxxxxxxxx>
- To: David Wells <bughunters@xxxxxxxxxxx>, "zsh-workers@xxxxxxx" <zsh-workers@xxxxxxx>
- Subject: Re: Zsh - Multiple DoS Vulnerabilities
- Date: Mon, 13 May 2019 23:44:25 +0200
- Authentication-results: amavisd4.gkg.net (amavisd-new); dkim=pass (2048-bit key) header.d=yahoo.co.uk
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.co.uk; s=s2048; t=1557783871; bh=E4qX0Jmubi51hHoX5NHer9VOhFAep6ycw4zOyGzwzjg=; h=From:References:To:Subject:Date:From:Subject; b=YOCQwQsJJf5AhAdwpNuS6csmgI85/d93Uv0D0kNd1b5Y6jkUai7ZFHl59vV37w+LBT3/p3S77ZOFk2RLIS5XDrLL81WustFRbwGdSVCs81evvCtrHjalvQCogMSOkSRqDa0bLcTmE5VFqw20vuIdbUTJqqQE3OUmB5dbXd59m81lmXghchqCyASpbaymmMv7mlQDxZ0y/wiqe3kSxS+Vs5FfB5JdP3wJtnM2onmsMXkDepxTzk+B8bP8IO2IPz0Rb36Y0icCjaaJASQBic7udI1iN6613UkvuSp1ZqKaZ+kim9ZpJbUn5Xo6VaXrhAJVXmEGWzUeYN7kUVr+uw0DXQ==
- In-reply-to: <CAH+w=7Y8d0h43rM_dHhbiT8nvL3-zxF8DUWTjn--hPX8sF7iaA@mail.gmail.com>
- List-help: <mailto:zsh-workers-help@zsh.org>
- List-id: Zsh Workers List <zsh-workers.zsh.org>
- List-post: <mailto:zsh-workers@zsh.org>
- List-unsubscribe: <mailto:zsh-workers-unsubscribe@zsh.org>
- Mailing-list: contact zsh-workers-help@xxxxxxx; run by ezmlm
- References: <CAAOKOsfSAR5aRBvEcyQKRzDCvOgRJdyRvVb9AXMq6d22RaUozQ@mail.gmail.com> <CAH+w=7Y8d0h43rM_dHhbiT8nvL3-zxF8DUWTjn--hPX8sF7iaA@mail.gmail.com>
> On Fri, May 10, 2019 at 8:04 AM David Wells <bughunters@xxxxxxxxxxx> wrote:
> > #4 Invalid read from *bin_print *in *builtin.c*
> > POC folder: *04_bin_print_(builtin.c_5009)*
This seems to be very similar to #6: string to int conversion
overflowing to a negative number. In this case you can reproduce it
with just:
printf '%4444444444444$'
Note that narg below is of type int despite the use of strtoul().
Oliver
diff --git a/Src/builtin.c b/Src/builtin.c
index ca0ce35f5..a8f054c8a 100644
--- a/Src/builtin.c
+++ b/Src/builtin.c
@@ -4990,8 +4990,7 @@ bin_print(char *name, char **args, Options ops, int func)
narg = strtoul(c, &endptr, 0);
if (*endptr == '$') {
c = endptr + 1;
- DPUTS(narg <= 0, "specified zero or negative arg");
- if (narg > argc) {
+ if (narg <= 0 || narg > argc) {
zwarnnam(name, "%d: argument specifier out of range",
narg);
if (fout != stdout)
Messages sorted by:
Reverse Date,
Date,
Thread,
Author