From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: by sourceware.org (Postfix, from userid 48) id 549323861870; Wed, 19 Aug 2020 01:38:32 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 549323861870 From: "dominik.b.czarnota+bugzilla at gmail dot com" To: glibc-bugs@sourceware.org Subject: [Bug math/25487] sinl() stack corruption from crafted input (CVE-2020-10029) Date: Wed, 19 Aug 2020 01:38:31 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: glibc X-Bugzilla-Component: math X-Bugzilla-Version: unspecified X-Bugzilla-Keywords: X-Bugzilla-Severity: normal X-Bugzilla-Who: dominik.b.czarnota+bugzilla at gmail dot com X-Bugzilla-Status: RESOLVED X-Bugzilla-Resolution: FIXED X-Bugzilla-Priority: P2 X-Bugzilla-Assigned-To: unassigned at sourceware dot org X-Bugzilla-Target-Milestone: 2.32 X-Bugzilla-Flags: security+ X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: http://sourceware.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: glibc-bugs@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Glibc-bugs mailing list List-Unsubscribe: , List-Archive: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Aug 2020 01:38:32 -0000 https://sourceware.org/bugzilla/show_bug.cgi?id=3D25487 Disconnect3d changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |dominik.b.czarnota+bugzilla | |@gmail.com --- Comment #9 from Disconnect3d --- (In reply to Guido Vranken from comment #0) > This has been tested on x64 Linux with both the Ubuntu glibc and the > latest git glibc. Btw since Ubuntu 18.04 and 20.04 both seems patched as of today, if anyone wants to play with this, it can be reproduced on e.g. gcc:9.3 docker image (https://hub.docker.com/layers/gcc/library/gcc/9.3/images/sha256-dd7c100e12= ddbf4178f5cd524a869fa54f453d35bf1b5f287ec6b70e3230c2e4?context=3Dexplore), or by using the following docker image (https://hub.docker.com/layers/disconnect3d/repro-cve-2020-10029/latest/ima= ges/sha256-0d7cf62eee140c9a0039945f8fe2ff3c53b7670b663cb67feef57878ab92ee06= ?context=3Dexplore) and command where I compiled the example in the cve-2020-10029 directory: docker run --rm -it --cap-drop=3DALL --net=3Dnone disconnect3d/repro-cve-20= 20-10029 /cve-2020-10029/a.out --=20 You are receiving this mail because: You are on the CC list for the bug.=