mirror of
git://sourceware.org/git/glibc.git
synced 2025-04-12 14:21:18 +08:00
iconv: Accept redundant shift sequences in IBM1364 [BZ #26224]
The IBM1364, IBM1371, IBM1388, IBM1390 and IBM1399 character sets share converter logic (iconvdata/ibm1364.c) which would reject redundant shift sequences when processing input in these character sets. This led to a hang in the iconv program (CVE-2020-27618). This commit adjusts the converter to ignore redundant shift sequences and adds test cases for iconv_prog hangs that would be triggered upon their rejection. This brings the implementation in line with other converters that also ignore redundant shift sequences (e.g. IBM930 etc., fixed in commit 692de4b3960d). Reviewed-by: Carlos O'Donell <carlos@redhat.com> (cherry picked from commit 9a99c682144bdbd40792ebf822fe9264e0376fb5)
This commit is contained in:
parent
7df507808c
commit
df31c7ca92
5
NEWS
5
NEWS
@ -26,6 +26,8 @@ The following bugs are resolved with this release:
|
||||
[25933] Off by one error in __strncmp_avx2
|
||||
[25966] Incorrect access of __x86_shared_non_temporal_threshold for x32
|
||||
[25976] nss_compat: internal_end*ent may clobber errno, hiding ERANGE
|
||||
[26224] iconv hangs when converting some invalid inputs from several IBM
|
||||
character sets (CVE-2020-27618)
|
||||
[26248] Incorrect argument types for INLINE_SETXID_SYSCALL
|
||||
[26332] Incorrect cache line size load causes memory corruption in memset
|
||||
[26383] bind_textdomain_codeset doesn't accept //TRANSLIT anymore
|
||||
@ -52,6 +54,9 @@ Security related changes:
|
||||
Dytrych of the Cisco Security Assessment and Penetration Team (See
|
||||
TALOS-2020-1019).
|
||||
|
||||
CVE-2020-27618: An infinite loop has been fixed in the iconv program when
|
||||
invoked with input containing redundant shift sequences in the IBM1364,
|
||||
IBM1371, IBM1388, IBM1390, or IBM1399 character sets.
|
||||
|
||||
Version 2.31
|
||||
|
||||
|
@ -102,12 +102,16 @@ hangarray=(
|
||||
"\x00\x80;-c;IBM1161;UTF-8//TRANSLIT//IGNORE"
|
||||
"\x00\xdb;-c;IBM1162;UTF-8//TRANSLIT//IGNORE"
|
||||
"\x00\x70;-c;IBM12712;UTF-8//TRANSLIT//IGNORE"
|
||||
# These are known hangs that are yet to be fixed:
|
||||
# "\x00\x0f;-c;IBM1364;UTF-8"
|
||||
# "\x00\x0f;-c;IBM1371;UTF-8"
|
||||
# "\x00\x0f;-c;IBM1388;UTF-8"
|
||||
# "\x00\x0f;-c;IBM1390;UTF-8"
|
||||
# "\x00\x0f;-c;IBM1399;UTF-8"
|
||||
"\x00\x0f;-c;IBM1364;UTF-8"
|
||||
"\x0e\x0e;-c;IBM1364;UTF-8"
|
||||
"\x00\x0f;-c;IBM1371;UTF-8"
|
||||
"\x0e\x0e;-c;IBM1371;UTF-8"
|
||||
"\x00\x0f;-c;IBM1388;UTF-8"
|
||||
"\x0e\x0e;-c;IBM1388;UTF-8"
|
||||
"\x00\x0f;-c;IBM1390;UTF-8"
|
||||
"\x0e\x0e;-c;IBM1390;UTF-8"
|
||||
"\x00\x0f;-c;IBM1399;UTF-8"
|
||||
"\x0e\x0e;-c;IBM1399;UTF-8"
|
||||
"\x00\x53;-c;IBM16804;UTF-8//TRANSLIT//IGNORE"
|
||||
"\x00\x41;-c;IBM274;UTF-8//TRANSLIT//IGNORE"
|
||||
"\x00\x41;-c;IBM275;UTF-8//TRANSLIT//IGNORE"
|
||||
|
@ -158,24 +158,14 @@ enum
|
||||
\
|
||||
if (__builtin_expect (ch, 0) == SO) \
|
||||
{ \
|
||||
/* Shift OUT, change to DBCS converter. */ \
|
||||
if (curcs == db) \
|
||||
{ \
|
||||
result = __GCONV_ILLEGAL_INPUT; \
|
||||
break; \
|
||||
} \
|
||||
/* Shift OUT, change to DBCS converter (redundant escape okay). */ \
|
||||
curcs = db; \
|
||||
++inptr; \
|
||||
continue; \
|
||||
} \
|
||||
if (__builtin_expect (ch, 0) == SI) \
|
||||
{ \
|
||||
/* Shift IN, change to SBCS converter. */ \
|
||||
if (curcs == sb) \
|
||||
{ \
|
||||
result = __GCONV_ILLEGAL_INPUT; \
|
||||
break; \
|
||||
} \
|
||||
/* Shift IN, change to SBCS converter (redundant escape okay). */ \
|
||||
curcs = sb; \
|
||||
++inptr; \
|
||||
continue; \
|
||||
|
Loading…
x
Reference in New Issue
Block a user