predict-g1yyh crashes when printing predictions

Bug #553140 reported by Norvald H. Ryeng
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
predict (Debian)
Fix Released
Unknown
predict (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: predict

A buffer overflow makes predict-g1yyh crash when printing predictions (p, v, s, n and o commands).

The attached patch extends header line 2 (head2) with an extra byte for the terminating \0 and shortens two strings that were 1 byte too long.

Related branches

Revision history for this message
Norvald H. Ryeng (ryeng) wrote :
Ciemon Dunville (ciemon)
Changed in predict (Ubuntu):
status: New → Confirmed
status: Confirmed → In Progress
assignee: nobody → Ciemon Dunville (ciemon)
Dave Walker (davewalker)
Changed in predict (Ubuntu):
status: In Progress → Fix Committed
Changed in predict (Debian):
status: Unknown → New
Revision history for this message
Fabrice Coutadeur (fabricesp) wrote :

Hi,
To request sponsorship, please do not use the Fix commited status (Confirmed or New is better) and unassign yourself from the bug report.
Fixing it.

Changed in predict (Ubuntu):
assignee: Ciemon Dunville (ciemon) → nobody
status: Fix Committed → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package predict - 2.2.3-2ubuntu2

---------------
predict (2.2.3-2ubuntu2) lucid; urgency=low

  * debian/patches/180_reworked_gui.diff: resizes and repositions
    widgets after GTK2 changes. Patch courtesy of Norvald H. Ryeng
    (LP: #555706)
  * debian/patches/141_buffer_overflow.diff: Fix a buffer overflow that
    makes predict-g1yyh crash when printing predictions (p, v, s, n and
    o commands). Patch courtesy of Norvald H. Ryeng (LP: #553140)
 -- Ciemon Dunville <email address hidden> Tue, 13 Apr 2010 18:53:40 +0100

Changed in predict (Ubuntu):
status: Confirmed → Fix Released
Changed in predict (Debian):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.