3 ms·
This doesn't even seem like a legitimate security vulnerability at all, just a generic behavior bug. I'm guessing there are countless bugs like this in a common
by staunch 4y ago
This doesn't even seem like a legitimate security vulnerability at all, just a generic behavior bug. I'm guessing there are countless bugs like this in a common Linux userland.
I'd argue that the security vulnerability only exist in any program which passes untrusted user input to zgrep, which would be an obviously insecure thing to do.
Unless zgrep claims its safe against untrusted user input? But that would be weird and surprising.
- TheDong 4y ago16 years ago, there was a bug reported to zgrep where files with 1 newline caused it to behave incorrectly. It was patched without a CVE https://git.savannah.gnu.org/cgit/gzip.git/commit/zgrep.in?id=a7528501d19c16640044bc0ff86a6eab8d4d637b https://git.savannah.gnu.org/cgit/gzip.git/commit/zgrep.in?i... This year, there was a bug reported to zgrep where files with 2 newlines caused it to behave incorrectly. It got a CVE and a front page hacker news post. I give it very good odds this vulnerability has seen next to zero exploitation in the wild in either of the two cases above.
- bombcar 4y agoSo we’re 16 years out from the three new line bug.
- _Algernon_ 4y agohttps://xkcd.com/605/ https://xkcd.com/605/