[BusyBox 0000577]: Two minor format string problems in ln

bugs at busybox.net bugs at busybox.net
Thu Dec 15 03:06:58 UTC 2005


The following issue has been CLOSED 
====================================================================== 
http://busybox.net/bugs/view.php?id=577 
====================================================================== 
Reported By:                johnny
Assigned To:                BusyBox
====================================================================== 
Project:                    BusyBox
Issue ID:                   577
Category:                   Security
Reproducibility:            always
Severity:                   crash
Priority:                   normal
Status:                     closed
Resolution:                 open
Fixed in Version:           
====================================================================== 
Date Submitted:             12-02-2005 17:55 PST
Last Modified:              12-14-2005 19:06 PST
====================================================================== 
Summary:                    Two minor format string problems in ln
Description: 
The error messages for the ln applet pass a user supplied string as the
first argument to the bb_error_msg function.  This function interprets the
string as a format string leading to a segfault.

The issue is relatively minor since the ln applet seems to be marked
_BB_SUID_NEVER.
====================================================================== 

---------------------------------------------------------------------- 
 landley - 12-14-05 19:06  
---------------------------------------------------------------------- 
Mostly already fixed, last bits done in svn 12841 

Issue History 
Date Modified   Username       Field                    Change               
====================================================================== 
12-02-05 17:55  johnny         New Issue                                    
12-02-05 17:55  johnny         Status                   new => assigned     
12-02-05 17:55  johnny         Assigned To               => BusyBox         
12-14-05 19:06  landley        Status                   assigned => closed  
12-14-05 19:06  landley        Note Added: 0000768                          
======================================================================




More information about the busybox-cvs mailing list