[CVE-2018-17942] vasnprintf: Fix heap memory overrun bug. 62/275062/1 accepted/tizen_7.0_base accepted/tizen_7.0_base_hotfix accepted/tizen_7.0_base_tool accepted/tizen_7.0_base_tool_hotfix accepted/tizen_8.0_base accepted/tizen_9.0_base accepted/tizen_base accepted/tizen_base_tool tizen_7.0_base tizen_7.0_base_hotfix tizen_8.0_base tizen_9.0_base tizen_base accepted/tizen/7.0/base/20230714.003028 accepted/tizen/7.0/base/hotfix/20230714.003840 accepted/tizen/7.0/base/tool/20221028.122232 accepted/tizen/7.0/base/tool/hotfix/20221115.090817 accepted/tizen/8.0/base/20231005.045008 accepted/tizen/9.0/base/20241030.075444 accepted/tizen/base/20230714.003433 accepted/tizen/base/tool/20220517.015812 accepted/tizen/base/tool/20220530.211849 submit/tizen_7.0_base/20221028.201101 submit/tizen_7.0_base_hotfix/20221115.161601 submit/tizen_base/20220517.015433 submit/tizen_base/20220527.062142 tizen_7.0_m2_release tizen_8.0_m2_release tizen_9.0_m2_release
authorDongHun Kwak <dh0128.kwak@samsung.com>
Mon, 16 May 2022 07:02:42 +0000 (16:02 +0900)
committerDongHun Kwak <dh0128.kwak@samsung.com>
Mon, 16 May 2022 07:02:42 +0000 (16:02 +0900)
commit180342ac60b2083fa2ba4d4ec88680248ec4d6dd
treea7297eb246bf736db1fec8507a1122943f27caa0
parent080a1e4cf99b47ffd5386c34af685f7ffd0a4faa
[CVE-2018-17942] vasnprintf: Fix heap memory overrun bug.

Reported by Ben Pfaff <blp@cs.stanford.edu> in
<https://lists.gnu.org/archive/html/bug-gnulib/2018-09/msg00107.html>.

* lib/vasnprintf.c (convert_to_decimal): Allocate one more byte of
memory.
* tests/test-vasnprintf.c (test_function): Add another test.

Change-Id: I107d30510c01c28390f6a61c4034ea5fe4d20d80
packaging/CVE-2018-17942.patch [new file with mode: 0644]
packaging/patch.spec