most dumps core when viewing file

Bug #361804 reported by Christian Hudon
6
Affects Status Importance Assigned to Milestone
most (Ubuntu)
In Progress
Undecided
Oskar Wallgren

Bug Description

Binary package hint: most

Ubuntu: hardy 8.04.2 LTS
Package: most
Package version: 4.10.2-5

When viewing the attached file (initgroup.patch2) with most, I get a core dump when viewing the file. I'm not sure if this exploitable or not, but I've flagged this as a security vulnerability to be safe. File viewers shouldn't dump core.

Revision history for this message
Christian Hudon (chrish) wrote :
Revision history for this message
Kees Cook (kees) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I cannot reproduce the crashes you're seeing. You may want to read https://wiki.ubuntu.com/DebuggingProcedures

I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

security vulnerability: yes → no
visibility: private → public
Revision history for this message
Oskar Wallgren (oskar-wallgren13) wrote :

I don't see the core dump either but the file doesn't open correctly.

>>$ file initgroups.patch2
>>initgroups.patch2: RCS/CVS diff output, ASCII text, with CR line terminators

Your file has a 0Dh line terminator and is probably made on a Apple Macintosh OS 9 or earlier.

The quick fix for anyone who runs into a problem like this is to open the file in a text editor that reads it (gedit/pluma) and save as and there will be an option to choose line ending for Linux/Unix. I'll probe into this and see if there are other bug reports out there.

Changed in most (Ubuntu):
assignee: nobody → Oskar Wallgren (oskar-wallgren13)
status: New → In Progress
Revision history for this message
Oskar Wallgren (oskar-wallgren13) wrote :

Programs less and more doesn't do to well with the file either.

Revision history for this message
Benjamin Mako Hill (mako) wrote :

The new version of most that I've uploaded to Debian (5.2.0) doesn't crash when opening the file or have any other problem. It doesn't look great and much of doesn't seem to be displayed at all, but it doesn't look great in less or more either.

There's at least one bug here, but the severity is much lower.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.