From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 486 invoked by alias); 18 Jan 2017 12:13:04 -0000 Mailing-List: contact cygwin-apps-help@cygwin.com; run by ezmlm Precedence: bulk Sender: cygwin-apps-owner@cygwin.com List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Mail-Followup-To: cygwin-apps@cygwin.com Received: (qmail 456 invoked by uid 89); 18 Jan 2017 12:13:03 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-0.8 required=5.0 tests=AWL,BAYES_00,KAM_LAZY_DOMAIN_SECURITY,RCVD_IN_DNSWL_NONE,T_HK_NAME_DR autolearn=no version=3.3.2 spammy=SECURITY, Hx-languages-length:1524, H*RU:sk:mrelaye, H*r:sk:mrelaye X-HELO: mout.kundenserver.de Received: from mout.kundenserver.de (HELO mout.kundenserver.de) (212.227.17.10) by sourceware.org (qpsmtpd/0.93/v0.84-503-g423c35a) with ESMTP; Wed, 18 Jan 2017 12:12:54 +0000 Received: from [192.168.2.11] ([91.40.173.27]) by mrelayeu.kundenserver.de (mreue104 [212.227.15.183]) with ESMTPSA (Nemesis) id 0LfSYr-1cnUYH0U5B-00p30n for ; Wed, 18 Jan 2017 13:12:52 +0100 Subject: Re: [SECURITY] libidn - locale specific error in test suite To: cygwin-apps@cygwin.com References: <90dee62a-dc34-f83a-7094-8e0df688d801@cygwin.com> <20381568-c93e-1517-0f3d-579a5e6ac3fa@volkerzell.de> <20170109142640.GC843@calimero.vinschen.de> From: "Dr. Volker Zell" Message-ID: <86acc3c1-23ff-d76c-f7c8-c3cefcd567fa@volkerzell.de> Date: Wed, 18 Jan 2017 12:13:00 -0000 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.6.0 MIME-Version: 1.0 In-Reply-To: <20170109142640.GC843@calimero.vinschen.de> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-UI-Out-Filterresults: notjunk:1;V01:K0:PaIkhrOwiKM=:nz0EEIjY+ER22+HkZSWP+w 352RYugzYIaQ1bEHZpnbBBxdI5u9nH5Jq4NWGr5ntU63mh6bBtWcMvHMKh5P1fdw+R6+Jyjc8 3hEG8Bl4hMxrg5stz4R19QxCfAx3EM8MqRyAeECs1QY7ExZYCwkhwrLZXx2WDVvnl+vQ+0mlV bOxwaFqyw3w14RVYSTTzsmBWvMFjEnS7LAdcip1D6/5kMBEgId5npvOu5kfiZ92yV6fYoVHKE OIlg6kqufBaqakYZNt+Q0vvKE/eJlU5hCC7/ntWYzOsbBY9TYzvuTkNQvq826cDWPRl3RaZXs ANP1o6260CFoksxuRgCK+0RtbqHDiXj2jDb/skhJ9tRx7zAAd5oW/iX89msHU7GghF4uMyE/A FopZ4UikzC5W+o2+Ro5JYhOLEpLioDcbl+hqzUGXbma2HXRro3qs56kNbhVWFuvXWM6fyKEpu RfQjuzhhXoZ2QiUaDCZggdE57l6TspgubvHuQHwbm3ZfQ9uJgYow+QqueqrHYGBZGs5R0hZQP PhMN2EMnZUxBNdjFlNnxwp3IAGm8gl2J1HR6QQHxw8y/f2qeHiDKTPSayrVruDOhXEZVAFuHd qS7bcVHLrd+BJcT9HhdTDxr+mfjn/hBiDa8oKeV/WHneUX4HKi4YEwk4D487hrXQSzEcGzTTM casrhNxnjcoBUWr/1yn7LRMIb5LTIG7URbviKn9NfgKFT1/MvRQn9JxSc9uHBqfcs9mtWD3X0 mwMx+Z82PXrfQ1ib X-IsSubscribed: yes X-SW-Source: 2017-01/txt/msg00022.txt.bz2 On 09.01.2017 15:26, Corinna Vinschen wrote: > On Jan 3 11:53, Dr. Volker Zell wrote: >> On 29.12.2016 21:49, Yaakov Selkowitz wrote: >>> On 2016-09-30 01:43, Dr. Volker Zell wrote: >>>>>>>>> Yaakov Selkowitz writes: >>>> >>>> > Dr. Volker, >>>> > Several security vulnerabilities have been announced for >>>> libidn, which are fixed >>>> > in 1.33: >>>> >>>> > >>>> https://lists.gnu.org/archive/html/help-libidn/2016-07/msg00009.html >>>> >>>> Noted (and also your other mails), will work on it as soon as real >>>> work permits. >>> >>> Ping? >>> >> >> Hi >> >> Just tried packaging libidn-1.33 and found a locale specific error in the >> test suite (Which was working fine with my latest build). When running under >> strace I get: >> [...] >> : 37 4387 [main] test-localename 11148 write: 1 = write(2, 0x1004060B9, >> 1) >> 183 32 4419 [main] test-localename 11148 write: 3 = write(2, >> 0xFFFFC9F1, 3) >> : assertion ' 30 4449 [main] test-localename 11148 write: 13 = write(2, >> 0x1004060BC, 13) >> strcmp (name, "fr_FR.UTF-8") == 0 30 4479 [main] test-localename 11148 >> write: 33 = write(2, 0x100406168, 33) >> ' failed >> [...] >> >> The source code can be found in the file (after unpacking of >> https://ftp.gnu.org/gnu/libidn/libidn-1.33.tar.gz) >> >> o .../libidn-1.33-1.x86_64/src/libidn-1.33/lib/gltests/test-localename.c > > Do you have a self-contained testcase, by any chance? No, just the testcase from the testsuite in libidn. Ciao Volker