Package: gettext
Version: 0.19.3-1

The attached (slightly corrupted) MO file crashes msgunfmt:

$ msgunfmt messages.mo
Segmentation fault

I suspect there's a integer overflow somewhere.


This bug was brought to you by American fuzzy lop:
http://lcamtuf.coredump.cx/afl/


-- System Information:
Debian Release: jessie/sid
 APT prefers unstable
 APT policy: (990, 'unstable'), (500, 'experimental')
Architecture: i386 (x86_64)
Foreign Architectures: amd64

Kernel: Linux 3.2.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages gettext depends on:
ii  dpkg           1.17.21
ii  gettext-base   0.19.3-1
ii  install-info   5.2.0.dfsg.1-5
ii  libc6          2.19-13
ii  libcroco3      0.6.8-3
ii  libglib2.0-0   2.42.1-1
ii  libgomp1       4.9.2-1
ii  libncurses5    5.9+20140913-1
ii  libtinfo5      5.9+20140913-1
ii  libunistring0  0.9.3-5.2
ii  libxml2        2.9.2+dfsg1-1

Versions of packages gettext recommends:
ii  autopoint         0.19.3-1
ii  curl              7.38.0-3
ii  libasprintf-dev   0.19.3-1
ii  libgettextpo-dev  0.19.3-1
ii  wget              1.16-3

--
Jakub Wilk

Attachment: messages.mo
Description: Binary data

Reply via email to