jfsutils 1.1.11 resolves buffer overflow, loops

Bug #57595 reported by Simon Kuhn
4
Affects Status Importance Assigned to Milestone
jfsutils (Ubuntu)
Fix Released
Low
Martin Pitt

Bug Description

jfsutils 1.1.11 was released 2006-06-05. Changelog:

New in 1.1.11 - 2006-06-05
* Fix infinite loop when mkfs.jfs is invoked with -c
* avoid infinite loop in xTree_binsrch_page
* Fix buffer overflow
* Fix segfault on s390
* Fix segfault in markImap
* Add compiler flags to generate useful warnings
* Code cleanup

already packaged in Debian unstable. Previous revisions between 1.1.8 and 1.1.11 also reduce memory usage and resolve a stack overflow according to the changelog.

Revision history for this message
Alexandre Vassalotti (avassalotti) wrote :

Debian changelog:

jfsutils (1.1.11-1) unstable; urgency=medium

  * new upstream release fixing stack buffer overflow (Closes: #343638)
  * keep only reference to GPL in debian/copyright
  * mark udeb package as such properly and create dependencies
    (Closes: #381245, thanks to Frans Pop <email address hidden> for the patch)

 -- Stefan Hornburg (Racke) <email address hidden> Wed, 2 Aug 2006 21:15:09 +0200

Revision history for this message
Alexandre Vassalotti (avassalotti) wrote :
Revision history for this message
Alexandre Vassalotti (avassalotti) wrote :
Revision history for this message
Alexandre Vassalotti (avassalotti) wrote :
Revision history for this message
Kees Cook (kees) wrote :

Thanks for the report!

For a security update, this is a pretty large diff. Looking at the buffer overflow that got fixed[1], I think the situation needed to abuse it aren't realistic.

A new jfsutils will be part of edgy+1, at which time these problems will be fixed.

[1] http://jfs.cvs.sourceforge.net/jfs/jfsutils/libfs/fssubs.c?r1=1.20&r2=1.21

Revision history for this message
Martin Pitt (pitti) wrote :

Thanks, Kees, for the review! Setting to 'in progress', will close after the feisty autosync process.

Changed in jfsutils:
assignee: nobody → pitti
importance: Undecided → Low
status: Unconfirmed → In Progress
Revision history for this message
Martin Pitt (pitti) wrote :

1.1.11 is in Feisty for a while.

Changed in jfsutils:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.