Re: Malicious translation file can cause buffer overflow

2015-05-19 Thread Mike Frysinger
On 01 May 2015 01:13, Pádraig Brady wrote: > On 30/04/15 23:08, Trammell Hudson wrote: > > Description: > > The gettext translated messages for "Done", "Done(%d)" and "Exit %d" > > in jobs.c are copied to a static allocated buffer. A user could set the > > LANGUAGE variable to point to a malicious

Re: Malicious translation file can cause buffer overflow

2015-04-30 Thread Pádraig Brady
On 30/04/15 23:08, Trammell Hudson wrote: > Configuration Information [Automatically generated, do not change]: > Machine: x86_64 > OS: linux-gnu > Compiler: gcc > Compilation CFLAGS: -DPROGRAM='bash' -DCONF_HOSTTYPE='x86_64' > -DCONF_OSTYPE='linux-gnu' -DCONF_MACHTYPE='x86_64-unknown-linux-gnu'

Re: Malicious translation file can cause buffer overflow

2015-04-30 Thread Chet Ramey
On 4/30/15 6:08 PM, Trammell Hudson wrote: > Bash Version: 4.3 > Patch Level: 30 > Release Status: release > > > Description: > The gettext translated messages for "Done", "Done(%d)" and "Exit %d" > in jobs.c are copied to a static allocated buffer. A user could set the > LANGUAGE variable to p

Malicious translation file can cause buffer overflow

2015-04-30 Thread Trammell Hudson
Configuration Information [Automatically generated, do not change]: Machine: x86_64 OS: linux-gnu Compiler: gcc Compilation CFLAGS: -DPROGRAM='bash' -DCONF_HOSTTYPE='x86_64' -DCONF_OSTYPE='linux-gnu' -DCONF_MACHTYPE='x86_64-unknown-linux-gnu' -DCONF_VENDOR='unknown' -DLOCALEDIR='/tmp/local/share