Debian Bug report logs - #695307
tcpick thinko and patch

version graph

Package: tcpick; Maintainer for tcpick is Debian Security Tools Packaging Team <pkg-security-team@lists.alioth.debian.org>; Source for tcpick is src:tcpick (PTS, buildd, popcon).

Reported by: "Dr. David Alan Gilbert" <dave@treblig.org>

Date: Thu, 6 Dec 2012 20:51:02 UTC

Severity: normal

Found in version tcpick/0.2.1-6

Fixed in version 0.2.1-6.1

Done: Raphael Hertzog <hertzog@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, William Vera <billy@billy.com.mx>:
Bug#695307; Package tcpick. (Thu, 06 Dec 2012 20:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Dr. David Alan Gilbert" <dave@treblig.org>:
New Bug report received and forwarded. Copy sent to William Vera <billy@billy.com.mx>. (Thu, 06 Dec 2012 20:51:05 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Dr. David Alan Gilbert" <dave@treblig.org>
To: submit@bugs.debian.org
Subject: tcpick thinko and patch
Date: Thu, 6 Dec 2012 20:48:26 +0000
Package: tcpick
Version: 0.2.1-6

This started off as an ubuntu bug:
https://bugs.launchpad.net/ubuntu/+source/tcpick/+bug/1086534

There's a thinko/cut-n-paste in time.c:time_ascii where there is
an incorrect length memset; this causes fortify to kill it
in the Ubuntu built versions.

I don't see any upstream activity for years, so I'm not sure
there is really anywhere to report it there.

Dave

Here is my patch:

--- ../../../tcpick-0.2.1/src/time.c    2005-01-09 00:21:44.000000000 +0000
+++ src/time.c  2012-12-06 20:11:10.041288135 +0000
@@ -42,7 +42,7 @@
   tzp = (struct timezone * ) S_malloc( sizeof(struct timezone) );  

   memset(tp,  0, sizeof(struct timeval));  
-  memset(tzp, 0, sizeof(struct timeval));  
+  memset(tzp, 0, sizeof(struct timezone)); 

   if(gettimeofday(tp, tzp)) {


-- 
 -----Open up your eyes, open up your mind, open up your code -------   
/ Dr. David Alan Gilbert    |       Running GNU/Linux       | Happy  \ 
\ gro.gilbert @ treblig.org |                               | In Hex /
 \ _________________________|_____ http://www.treblig.org   |_______/



Reply sent to Raphael Hertzog <hertzog@debian.org>:
You have taken responsibility. (Mon, 13 Jul 2015 12:06:04 GMT) (full text, mbox, link).


Notification sent to "Dr. David Alan Gilbert" <dave@treblig.org>:
Bug acknowledged by developer. (Mon, 13 Jul 2015 12:06:04 GMT) (full text, mbox, link).


Message #10 received at 695307-done@bugs.debian.org (full text, mbox, reply):

From: Raphael Hertzog <hertzog@debian.org>
To: "Dr. David Alan Gilbert" <dave@treblig.org>, 695307-done@bugs.debian.org
Subject: Re: Bug#695307: tcpick thinko and patch
Date: Mon, 13 Jul 2015 14:03:51 +0200
Version: 0.2.1-6.1

On Thu, 06 Dec 2012, Dr. David Alan Gilbert wrote:
> This started off as an ubuntu bug:
> https://bugs.launchpad.net/ubuntu/+source/tcpick/+bug/1086534
> 
> There's a thinko/cut-n-paste in time.c:time_ascii where there is
> an incorrect length memset; this causes fortify to kill it
> in the Ubuntu built versions.
> 
> I don't see any upstream activity for years, so I'm not sure
> there is really anywhere to report it there.

I (re)discovered this error by myself today while fixing the
GCC 5 build failure and I fixed it in the 0.2.1-6.1 upload I just
made.

Thanks for the report!

Cheers,
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 16 Aug 2015 07:25:39 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Jan 12 07:23:44 2018; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.