Yes, I keep spamming this trying to find an appropriate mailing list. I don't remember how or why I initially stumbled across this bug report (https://bugs.launchpad.net/ubuntu/+source/bc/+bug/1775776), but, given that I have some familiarity with GNU bc, I decided to fix some of the issues. Turns out, this also seems to fix the crashes reported here (https://www.openwall.com/lists/oss-security/2018/11/28/1). I think it would be a lot more useful to share this, as there isn't a lot to review. There are three bug fixes and some self-defensive checks in the runtime for malformed bytecode. Address Sanitizer tells me that these previously invalid memory references now just leak memory. I don't appear to have broken anything in thePlease send such patches upstream.
process, either. I'm not a member of any Debian mailing list, but I will try to watch for responses.
Greetings,
Yes, I keep spamming this trying to find an appropriate mailing list. I don't remember how or why I initially stumbled across this bug report (https://bugs.launchpad.net/ubuntu/+source/bc/+bug/1775776), but, given that I have some familiarity with GNU bc, I decided to fix some of the issues. Turns out, this also seems to fix the crashes reported here (https://www.openwall.com/lists/oss-security/2018/11/28/1). I think it would be a lot more useful to share this, as there isn't a lot to review. There are three bug fixes and some self-defensive checks in the runtime for malformed bytecode. Address Sanitizer tells me that these previously invalid memory references now just leak memory. I don't appear to have broken anything in the
process, either. I'm not a member of any Debian mailing list, but I will try to watch for responses.
Just trying to be somewhat helpful,
You do say it needs a better description, so I'm going to try to
give you a sense of what's going on.
I was really saying that whoever feels competent to decide to accept the Merge Request for the bc package ought to come up with a better
description for why they think the patch should be applied to the Debian package, but I'm sure your description will help too.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (2 / 14) |
Uptime: | 153:53:43 |
Calls: | 10,383 |
Files: | 14,054 |
Messages: | 6,417,842 |