[Bug 1400575] [NEW] sed segfaults on L command with long address lengths

Jodie Cunningham 1400575 at bugs.launchpad.net
Tue Dec 9 03:47:49 UTC 2014


Public bug reported:

To reproduce, run:
sed 'L222222' <<<d

These do not segfault:
sed 'L22222' <<<d
sed 'L2222222222222222222222222' <<<d


I do not have any expected behavior for this as it was just found by the fuzzer AFL.

System is AMD64
Distributor ID:	Ubuntu
Description:	Ubuntu 14.04.1 LTS
Release:	14.04
Codename:	trusty

sed:
  Installed: 4.2.2-4ubuntu1
  Candidate: 4.2.2-4ubuntu1
  Version table:
 *** 4.2.2-4ubuntu1 0
        500 http://us.archive.ubuntu.com/ubuntu/ trusty/main amd64 Packages
        100 /var/lib/dpkg/status

** Affects: sed (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to sed in Ubuntu.
https://bugs.launchpad.net/bugs/1400575

Title:
  sed segfaults on L command with long address lengths

Status in sed package in Ubuntu:
  New

Bug description:
  To reproduce, run:
  sed 'L222222' <<<d

  These do not segfault:
  sed 'L22222' <<<d
  sed 'L2222222222222222222222222' <<<d

  
  I do not have any expected behavior for this as it was just found by the fuzzer AFL.

  System is AMD64
  Distributor ID:	Ubuntu
  Description:	Ubuntu 14.04.1 LTS
  Release:	14.04
  Codename:	trusty

  sed:
    Installed: 4.2.2-4ubuntu1
    Candidate: 4.2.2-4ubuntu1
    Version table:
   *** 4.2.2-4ubuntu1 0
          500 http://us.archive.ubuntu.com/ubuntu/ trusty/main amd64 Packages
          100 /var/lib/dpkg/status

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sed/+bug/1400575/+subscriptions



More information about the foundations-bugs mailing list